CVE-2026-87828: Seraphinite Accelerator < 2.29.24 - Subscriber+ DoS via seraph_accel_State Update
The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscribers to write a malformed value that causes an uncaught error on every subsequent admin page load, making the entire admin area inaccessible to all administrators (denial of service).
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Seraphinite Accelerator WordPress pluginto a version that resolves this vulnerability.Fixed in 2.29.24
Event History
Frequently Asked Questions
Which users can exploit this issue?
Any authenticated user with a low-privilege account such as a subscriber can trigger it. Administrative privileges are not required.
What access does an attacker need?
The attacker needs a valid WordPress account so they can invoke the affected state-update AJAX action. The provided information does not indicate that unauthenticated exploitation is possible.
What is the operational impact if exploitation succeeds?
A malformed state value causes an uncaught error on each later admin page load. This makes the WordPress admin area inaccessible to all administrators.