Skip to content

Known CVE

Seraphinite Accelerator <= 2.29.18 - Cross-Site Scripting

The Seraphinite Accelerator plugin for WordPress up to and including 2.29.18 was vulnerable to reflected cross-site scripting through the seraph_accel_prep parameter. CacheExtractPreparePageParams() compared the expected HMAC against the JSON-decoded nonce with PHP's loose != operator, so a JSON boolean true satisfied the comparison and bypassed the signature check, and _CbContentFinishSkip() then concatenated the attacker-controlled selfTest field straight into the response body, letting unauthenticated attackers inject arbitrary scripts.

CVE-2026-17532

Medium2026CVSS 6.1CWE-79

cve2026 · wordpress · wp · wp-plugin · seraphinite · xss

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website