plugin

Seraphinite Accelerator Vulnerabilities

22 known security issues reported for the Seraphinite Accelerator WordPress plugin. Most recent disclosed Aug 4, 2026.

12 medium

Running Seraphinite Accelerator on your site? Check whether your installed version is affected.

Scan your site free

Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting

medium

The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up to, and including, 2.29.15. This is due to the CacheExtractPreparePageParams() function using PHP's loose inequality operator (!=) to compare the expected HMAC string aga...

CVSS:
6.1
Affected:
up to 2.29.18
Fixed in:
2.29.19
Disclosed:
Aug 4, 2026

CVE-2026-17532 on NVD →

Seraphinite Accelerator - Authenticated (Subscriber+) Exposure of Sensitive Information to an Unauthorized Actor vulnerability

medium

Authenticated (Subscriber+) Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS:
4.3
Affected:
up to 2.28.14
Fixed in:
2.28.15
Disclosed:
Mar 4, 2026

Seraphinite Accelerator <= 2.28.14 - Authenticated (Subscriber+) Exposure of Sensitive Information to an Unauthorized Actor

medium

The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.28.14 via the `seraph_accel_api` AJAX action with `fn=GetData`. This is due to the `OnAdminApi_GetData()` function not performing any capability checks. This makes it possible for aut...

CVSS:
4.3
Affected:
up to 2.28.14
Fixed in:
2.28.15
Disclosed:
Mar 3, 2026

CVE-2026-3058 on NVD →

Seraphinite Accelerator <= 2.28.14 - Missing Authorization to Authenticated (Subscriber+) Log Clearing

medium

The Seraphinite Accelerator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `seraph_accel_api` AJAX action with `fn=LogClear` in all versions up to, and including, 2.28.14. This makes it possible for authenticated attackers, with Subscriber-level access a...

CVSS:
4.3
Affected:
up to 2.28.14
Fixed in:
2.28.15
Disclosed:
Mar 3, 2026

CVE-2026-3056 on NVD →

Seraphinite Accelerator <= 2.27.21 - Cross-Site Request Forgery to Multiple Administrative Actions

medium

The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing or incorrect nonce validation on the 'OnAdminApi_CacheOpBegin' function. This makes it possible for unauthenticated attackers to perform several administrati...

CVSS:
4.3
Affected:
up to 2.27.21
Fixed in:
2.27.22
Disclosed:
Apr 29, 2025

CVE-2025-6059 on NVD →

Seraphinite Accelerator <= 2.22.15 (2.21.13 PRO) - Authenticated (Subscriber+) Information Exposure

medium

The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.22.15 (2.21.13 PRO). This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 2.22.15
Fixed in:
2.22.16
Disclosed:
Dec 19, 2024

CVE-2024-54222 on NVD →

Seraphinite Accelerator [seraphinite-accelerator] < 2.20.48

unknown

[en] Insertion of Sensitive Information into Log File vulnerability in Seraphinite Solutions Seraphinite Accelerator.This issue affects Seraphinite Accelerator: from n/a through 2.20.47.

Affected:
up to 2.20.48
Fixed in:
2.20.48
Disclosed:
Mar 28, 2024

CVE-2024-22138 on NVD →

Seraphinite Accelerator [seraphinite-accelerator] < 2.21

unknown

[en] The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.20.52 via the OnAdminApi_HtmlCheck function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations...

Affected:
up to 2.21
Fixed in:
2.21
Disclosed:
Feb 28, 2024

CVE-2024-1568 on NVD →

Seraphinite Accelerator <= 2.20.52 - Authenticated (Subscriber+) Server-Side Request Forgery in OnAdminApi_HtmlCheck

medium

The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.20.52 via the OnAdminApi_HtmlCheck function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations origi...

CVSS:
6.4
Affected:
up to 2.20.52
Fixed in:
2.21
Disclosed:
Feb 27, 2024

CVE-2024-1568 on NVD →

Seraphinite Accelerator <= 2.20.47 - Unauthenticated Sensitive Information Exposure via Log File

medium

The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.47. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data from log files.

CVSS:
5.3
Affected:
up to 2.20.47
Fixed in:
2.20.48
Disclosed:
Jan 8, 2024

CVE-2024-22138 on NVD →

Seraphinite Accelerator [seraphinite-accelerator] < 2.20.29

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Seraphinite Solutions Seraphinite Accelerator allows Reflected XSS.This issue affects Seraphinite Accelerator: from n/a through 2.20.28.

Affected:
up to 2.20.29
Fixed in:
2.20.29
Disclosed:
Dec 14, 2023

CVE-2023-49740 on NVD →

Seraphinite Accelerator <= 2.20.28 - Reflected Cross-Site Scripting via rt

medium

The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘rt’ parameter in versions up to, and including, 2.20.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 2.20.28
Fixed in:
2.20.29
Disclosed:
Dec 1, 2023

CVE-2023-49740 on NVD →

Seraphinite Accelerator [seraphinite-accelerator] < 2.20.32

unknown

[en] The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to reset them

Affected:
up to 2.20.32
Fixed in:
2.20.32
Disclosed:
Nov 27, 2023

CVE-2023-5611 on NVD →

Seraphinite Accelerator [seraphinite-accelerator] < 2.20.29

unknown

[en] The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect

Affected:
up to 2.20.29
Fixed in:
2.20.29
Disclosed:
Nov 20, 2023

CVE-2023-5610 on NVD →

Seraphinite Accelerator [seraphinite-accelerator] < 2.20.29

unknown

[en] The Seraphinite Accelerator WordPress plugin before 2.2.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 2.20.29
Fixed in:
2.20.29
Disclosed:
Nov 20, 2023

CVE-2023-5609 on NVD →

Seraphinite Accelerator (Base, cache only) <= 2.20.31 - Cross-Site Request Forgery

medium

The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.20.31. This is due to missing nonce validation on the 'reset' case of the Init() function, the 'settImport' case of the _on_admin_action_act() function, and the OnInitAdminMode() function...

CVSS:
4.3
Affected:
up to 2.20.31
Fixed in:
2.20.32
Disclosed:
Oct 29, 2023

CVE-2023-5611 on NVD →

Seraphinite Accelerator [seraphinite-accelerator] < 2.20.32

unknown

The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.20.31. This is due to missing nonce validation on the 'reset' case of the Init() function, the 'settImport' case of the _on_admin_action_act() function, and the OnInitAdminMode() function...

Affected:
up to 2.20.32
Fixed in:
2.20.32
Disclosed:
Oct 29, 2023

Seraphinite Accelerator [seraphinite-accelerator] < 2.20.32

unknown

Update the WordPress Seraphinite Accelerator plugin to the latest available version (at least 2.20.32). An unknown person discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Seraphinite Accelerator Plugin. This could allow a malicious actor to force higher privileged users to execu...

Affected:
up to 2.20.32
Fixed in:
2.20.32
Disclosed:
Oct 29, 2023

Seraphinite Accelerator <= 2.20.28 - Reflected Cross-Site Scripting via 'rt'

medium

The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rt' parameter in all versions up to, and including, 2.20.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 2.20.28
Fixed in:
2.20.29
Disclosed:
Oct 27, 2023

CVE-2023-5609 on NVD →

Seraphinite Accelerator <= 2.20.28 - Arbitrary Redirect via 'redir'

medium

The Seraphinite Accelerator plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.20.28. This is due to insufficient validation on the redirect url supplied via the 'redir' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious si...

CVSS:
5.4
Affected:
up to 2.20.28
Fixed in:
2.20.29
Disclosed:
Oct 27, 2023

CVE-2023-5610 on NVD →

Seraphinite Accelerator [seraphinite-accelerator] < 2.22.16

unknown
Affected:
up to 2.22.16
Fixed in:
2.22.16

CVE-2024-54222 on NVD →

Seraphinite Accelerator [seraphinite-accelerator] < 2.27.22

unknown

The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing or incorrect nonce validation on the &#039;OnAdminApi_CacheOpBegin&#039; function. This makes it possible for unauthenticated attackers to perform several ad...

Affected:
up to 2.27.22
Fixed in:
2.27.22

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database