What is CVE-2026-28139?
CVE-2026-28139 is an unauthenticated PHP Object Injection vulnerability in the Ajax Search Lite plugin, affecting versions up to 4.14.4. It could allow remote code execution or unauthorized data access. Update to the latest plugin version to mitigate.
Azərbaycanca: CVE-2026-28139, Ajax Search Lite plaginin 4.14.4 və daha əvvəlki versiyalarında autentifikasiya olmadan PHP Object Injection zəifliyidir. Bu, uzaqdan kod icrasına və ya məlumatlara icazəsiz girişə səbəb ola bilər. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which versions of the Ajax Search Lite plugin are affected by CVE-2026-28139?
CVE-2026-28139 affects Ajax Search Lite plugin versions up to and including 4.14.4.
How can I protect against CVE-2026-28139?
To protect against this vulnerability, it is recommended to update the Ajax Search Lite plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.