Ajax Search Lite – Live Search & Filter <= 4.14.4 - Unauthenticated PHP Object Injection
high
The Ajax Search Lite – Live Search & Filter plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.14.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. I...
- CVSS:
- 8.1
- Affected:
- up to 4.14.4
- Fixed in:
- 4.14.5
- Disclosed:
- Aug 4, 2026
CVE-2026-28139 on NVD →
Ajax Search Lite <= 4.14.4 - Unauthenticated PHP Object Injection
high
The Ajax Search Lite plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.14.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is presen...
- CVSS:
- 8.1
- Affected:
- up to 4.14.4
- Fixed in:
- 4.14.5
- Disclosed:
- Aug 3, 2026
CVE-2026-16258 on NVD →
Ajax Search Lite – Live Search & Filter [ajax-search-lite] <= 4.13.3 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.This issue affects Ajax Search Lite: from n/a through <= 4.13.3.
- Affected:
- up to 4.13.3
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-48086 on NVD →
Ajax Search Lite <= 4.13.3 - Authenticated (Administrator+) PHP Object Injection
medium
The Ajax Search Lite plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.13.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vul...
- CVSS:
- 6.6
- Affected:
- up to 4.13.3
- Fixed in:
- 4.13.4
- Disclosed:
- Oct 21, 2025
CVE-2025-48086 on NVD →
Ajax Search Lite <= 4.13.1 - Missing Authorization to Unauthenticated Basic Information Exposure via ASL_Query in AJAX Search Handler
medium
The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in its AJAX search handler in all versions up to, and including, 4.13.1. This makes it possible for unauthenticated attackers to issue repeated AJAX requests to leak the content of any protected post in ro...
- CVSS:
- 5.3
- Affected:
- up to 4.13.1
- Fixed in:
- 4.13.2
- Disclosed:
- Aug 27, 2025
CVE-2025-7956 on NVD →
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.12.5
unknown
[en] The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 4.12.5
- Fixed in:
- 4.12.5
- Disclosed:
- Feb 21, 2025
CVE-2024-13585 on NVD →
Ajax Search Lite <= 4.12.4 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Ajax Search Lite – Live Search & Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.12.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissio...
- CVSS:
- 4.4
- Affected:
- up to 4.12.4
- Fixed in:
- 4.12.5
- Disclosed:
- Jan 31, 2025
CVE-2024-13585 on NVD →
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.12.4
unknown
[en] The Ajax Search Lite WordPress plugin before 4.12.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 4.12.4
- Fixed in:
- 4.12.4
- Disclosed:
- Dec 12, 2024
CVE-2024-10568 on NVD →
Ajax Search Lite <= 4.12.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Ajax Search Lite – Live Search & Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.12.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissio...
- CVSS:
- 4.4
- Affected:
- up to 4.12.3
- Fixed in:
- 4.12.4
- Disclosed:
- Nov 21, 2024
CVE-2024-10568 on NVD →
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.12.1
unknown
[en] The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks.
- Affected:
- up to 4.12.1
- Fixed in:
- 4.12.1
- Disclosed:
- Aug 6, 2024
CVE-2024-7084 on NVD →
Ajax Search Lite <= 4.12.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Ajax Search Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...
- CVSS:
- 4.4
- Affected:
- up to 4.12.1
- Fixed in:
- 4.12.2
- Disclosed:
- Aug 2, 2024
CVE-2024-8619 on NVD →
Ajax Search Lite < 4.12 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Ajax Search Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject a...
- CVSS:
- 5.5
- Affected:
- up to 4.12
- Fixed in:
- 4.12.1
- Disclosed:
- Jul 16, 2024
CVE-2024-7084 on NVD →
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.11.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Ernest Marcinko Ajax Search Lite allows Reflected XSS.This issue affects Ajax Search Lite: from n/a through 4.11.4.
- Affected:
- up to 4.11.5
- Fixed in:
- 4.11.5
- Disclosed:
- Feb 29, 2024
CVE-2024-21752 on NVD →
Ajax Search Lite <= 4.11.4 - Reflected Cross-Site Scripting
medium
The Ajax Search Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.11.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user a...
- CVSS:
- 6.1
- Affected:
- up to 4.11.4
- Fixed in:
- 4.11.5
- Disclosed:
- Jan 4, 2024
CVE-2024-21752 on NVD →
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.11.1
unknown
[en] The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 4.11.1
- Fixed in:
- 4.11.1
- Disclosed:
- Apr 24, 2023
CVE-2023-1420 on NVD →
Ajax Search Lite <= 4.11 - Reflected Cross-Site Scripting
high
The Ajax Search Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...
- CVSS:
- 7.2
- Affected:
- up to 4.11
- Fixed in:
- 4.11.1
- Disclosed:
- Apr 3, 2023
CVE-2023-1420 on NVD →
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.11.1
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions.
- Affected:
- up to 4.11.1
- Fixed in:
- 4.11.1
- Disclosed:
- Mar 15, 2023
CVE-2022-38456 on NVD →
Ajax Search Lite <= 4.10.3 - Missing Authorization leading to Authenticated (Subscriber+) Sensitive Information Disclosure
medium
The Ajax Search Lite plugin for WordPress is vulnerable to Missing Authorization (leading to Sensitive Information Disclosure) in versions up to, and including, 4.10.3 via the 'searchCF' function. This can allow subscriber-level attackers to extract sensitive data including post metadata from an unprotected Ajax endpoi...
- CVSS:
- 4.3
- Affected:
- up to 4.10.3
- Fixed in:
- 4.11
- Disclosed:
- Feb 6, 2023
CVE-2022-38456 on NVD →
Ajax Search Lite < 3.11 - Missing Authorization to Remote Code Execution
high
The Ajax Search Lite plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpdreams_ajaxinputcallback function in versions up to, and including, 3.10. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to bypass restricted actio...
- CVSS:
- 8.8
- Affected:
- up to 3.11
- Fixed in:
- 3.11
- Disclosed:
- Mar 26, 2015
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 3.11
unknown
The Ajax Search Lite plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpdreams_ajaxinputcallback function in versions up to, and including, 3.10. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to bypass restricted actio...
- Affected:
- up to 3.11
- Fixed in:
- 3.11
- Disclosed:
- Mar 26, 2015
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 3.0
unknown
Because of this vulnerability, any registered user to execute any function he wants with
1st param set to array($_POST).
Update the plugin.
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Mar 18, 2015
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 3.11
unknown
This vulnerability allows any registered user to execute any function he wants.
Upgrade the plugin.
- Affected:
- up to 3.11
- Fixed in:
- 3.11
- Disclosed:
- Mar 18, 2015
Ajax Search Lite < 3.11 - Remote Code Execution
critical
The Ajax Search Lite plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.10 via the TimThumb’s "Webshot" feature. This allows unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 3.11
- Fixed in:
- 3.11
- Disclosed:
- Jun 24, 2014
CVE-2014-4663 on NVD →
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 3.11
unknown
The Ajax Search Lite plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.10 via the TimThumb’s "Webshot" feature. This allows unauthenticated attackers to execute code on the server.
- Affected:
- up to 3.11
- Fixed in:
- 3.11
- Disclosed:
- Jun 24, 2014
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 3.11
unknown
Proof of Concept:
This will register an administrator with username "xADMIN" and password "xPASS":
POST request to: /wp-admin/admin-ajax.php?page=ajax-search-pro/backend/settings.php&action=wpdreams-ajaxinput
With POST data:
wpdreams_callback=wp_insert_user&user_login=xADMIN&us...
- Affected:
- up to 3.11
- Fixed in:
- 3.11
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.12.3
unknown
- Affected:
- up to 4.12.3
- Fixed in:
- 4.12.3
CVE-2024-8619 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database