CVE-2021-29654

HIGH

Stackpath Ajaxsearchpro < 4.20.8 - Insecure Deserialization

Title source: rule

Description

AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administration panel), leading to Remote Code execution.

Scores

CVSS v3 7.2
EPSS 0.0189
EPSS Percentile 83.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

stackpath/ajaxsearchpro < 4.20.8

Timeline

Published Apr 14, 2021
Tracked Since Feb 18, 2026