CVE-2026-87828
Seraphinite Accelerator < 2.29.24 - Subscriber+ DoS via seraph_accel_State Update
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscribers to write a malformed value that causes an uncaught error on every subsequent admin page load, making the entire admin area inaccessible to all administrators (denial of service).
| Vendor | unknown |
| Product | seraphinite accelerator |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown seraphinite accelerator
Be the first to know when new unknown vulnerabilities affecting unknown seraphinite accelerator are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Seraphinite Accelerator
0 < 2.29.24
References
Credits
รngel PS (drtz) WPScan