The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscribers to write a malformed value that causes an uncaught error on every subsequent admin page load, making the entire admin area inaccessible to all administrators (denial of service).
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscribers to write a malformed value that causes an uncaught error on every subsequent admin page load, making the entire admin area inaccessible to all administrators (denial of service). | |
| Title | Seraphinite Accelerator < 2.29.24 - Subscriber+ DoS via seraph_accel_State Update | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-16T06:00:16.463Z
Reserved: 2026-09-09T10:49:14.573Z
Link: CVE-2026-87828
No data.
Status : Received
Published: 2026-09-16T06:16:35.137
Modified: 2026-09-16T06:16:35.137
Link: CVE-2026-87828
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.