CVE-2026-16258

CRITICAL

Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST Endpoint

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-16258. PoCs published by exploitintel.

AI-analyzed exploit summary This repository provides a functional proof-of-concept for CVE-2026-16258, an unauthenticated PHP Object Injection vulnerability in the Ajax Search Lite WordPress plugin (< 4.14.5). The exploit leverages a deserialization sink in the plugin's search statistics REST endpoint to instantiate attacker-controlled classes, demonstrating impact via a canary gadget class that writes a marker file.

Description

The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.

Exploits (1)

github WORKING POC 7 stars
by exploitintel · cpoc
https://github.com/exploitintel/eip-pocs-and-cves/tree/main/CVE-2026-16258

This repository provides a functional proof-of-concept for CVE-2026-16258, an unauthenticated PHP Object Injection vulnerability in the Ajax Search Lite WordPress plugin (< 4.14.5). The exploit leverages a deserialization sink in the plugin's search statistics REST endpoint to instantiate attacker-controlled classes, demonstrating impact via a canary gadget class that writes a marker file.

Classification
Working Poc 100%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Ajax Search Lite WordPress plugin versions 0 to 4.14.4
No auth needed
Prerequisites: Search statistics feature must be admin-enabled (non-default) · A suitable POP chain must be present via another installed plugin/theme (demonstrated with a lab canary gadget)
mistral-large-3 · analyzed Aug 08, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/8487a2ce-cb4d-46b8-942e-334ac94cf115/

Scores

CVSS v3 9.8
EPSS 0.0047
EPSS Percentile 38.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
None/Ajax Search Lite < 4.14.5
Published Aug 07, 2026
Tracked Since Aug 07, 2026