Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
medium
The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up to, and including, 2.29.15. This is due to the CacheExtractPreparePageParams() function using PHP's loose inequality operator (!=) to compare the expected HMAC string aga...
- CVSS:
- 6.1
- Affected:
- up to 2.29.18
- Fixed in:
- 2.29.19
- Disclosed:
- Aug 4, 2026
CVE-2026-17532 on NVD →
Seraphinite Accelerator - Authenticated (Subscriber+) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
medium
Authenticated (Subscriber+) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
- CVSS:
- 4.3
- Affected:
- up to 2.28.14
- Fixed in:
- 2.28.15
- Disclosed:
- Mar 4, 2026
Seraphinite Accelerator <= 2.28.14 - Authenticated (Subscriber+) Exposure of Sensitive Information to an Unauthorized Actor
medium
The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.28.14 via the `seraph_accel_api` AJAX action with `fn=GetData`. This is due to the `OnAdminApi_GetData()` function not performing any capability checks. This makes it possible for aut...
- CVSS:
- 4.3
- Affected:
- up to 2.28.14
- Fixed in:
- 2.28.15
- Disclosed:
- Mar 3, 2026
CVE-2026-3058 on NVD →
Seraphinite Accelerator <= 2.28.14 - Missing Authorization to Authenticated (Subscriber+) Log Clearing
medium
The Seraphinite Accelerator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `seraph_accel_api` AJAX action with `fn=LogClear` in all versions up to, and including, 2.28.14. This makes it possible for authenticated attackers, with Subscriber-level access a...
- CVSS:
- 4.3
- Affected:
- up to 2.28.14
- Fixed in:
- 2.28.15
- Disclosed:
- Mar 3, 2026
CVE-2026-3056 on NVD →
Seraphinite Accelerator <= 2.27.21 - Cross-Site Request Forgery to Multiple Administrative Actions
medium
The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing or incorrect nonce validation on the 'OnAdminApi_CacheOpBegin' function. This makes it possible for unauthenticated attackers to perform several administrati...
- CVSS:
- 4.3
- Affected:
- up to 2.27.21
- Fixed in:
- 2.27.22
- Disclosed:
- Apr 29, 2025
CVE-2025-6059 on NVD →
Seraphinite Accelerator <= 2.22.15 (2.21.13 PRO) - Authenticated (Subscriber+) Information Exposure
medium
The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.22.15 (2.21.13 PRO). This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 2.22.15
- Fixed in:
- 2.22.16
- Disclosed:
- Dec 19, 2024
CVE-2024-54222 on NVD →
Seraphinite Accelerator [seraphinite-accelerator] < 2.20.48
unknown
[en] Insertion of Sensitive Information into Log File vulnerability in Seraphinite Solutions Seraphinite Accelerator.This issue affects Seraphinite Accelerator: from n/a through 2.20.47.
- Affected:
- up to 2.20.48
- Fixed in:
- 2.20.48
- Disclosed:
- Mar 28, 2024
CVE-2024-22138 on NVD →
Seraphinite Accelerator [seraphinite-accelerator] < 2.21
unknown
[en] The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.20.52 via the OnAdminApi_HtmlCheck function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations...
- Affected:
- up to 2.21
- Fixed in:
- 2.21
- Disclosed:
- Feb 28, 2024
CVE-2024-1568 on NVD →
Seraphinite Accelerator <= 2.20.52 - Authenticated (Subscriber+) Server-Side Request Forgery in OnAdminApi_HtmlCheck
medium
The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.20.52 via the OnAdminApi_HtmlCheck function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations origi...
- CVSS:
- 6.4
- Affected:
- up to 2.20.52
- Fixed in:
- 2.21
- Disclosed:
- Feb 27, 2024
CVE-2024-1568 on NVD →
Seraphinite Accelerator <= 2.20.47 - Unauthenticated Sensitive Information Exposure via Log File
medium
The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.47. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data from log files.
- CVSS:
- 5.3
- Affected:
- up to 2.20.47
- Fixed in:
- 2.20.48
- Disclosed:
- Jan 8, 2024
CVE-2024-22138 on NVD →
Seraphinite Accelerator [seraphinite-accelerator] < 2.20.29
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Seraphinite Solutions Seraphinite Accelerator allows Reflected XSS.This issue affects Seraphinite Accelerator: from n/a through 2.20.28.
- Affected:
- up to 2.20.29
- Fixed in:
- 2.20.29
- Disclosed:
- Dec 14, 2023
CVE-2023-49740 on NVD →
Seraphinite Accelerator <= 2.20.28 - Reflected Cross-Site Scripting via rt
medium
The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘rt’ parameter in versions up to, and including, 2.20.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 2.20.28
- Fixed in:
- 2.20.29
- Disclosed:
- Dec 1, 2023
CVE-2023-49740 on NVD →
Seraphinite Accelerator [seraphinite-accelerator] < 2.20.32
unknown
[en] The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to reset them
- Affected:
- up to 2.20.32
- Fixed in:
- 2.20.32
- Disclosed:
- Nov 27, 2023
CVE-2023-5611 on NVD →
Seraphinite Accelerator [seraphinite-accelerator] < 2.20.29
unknown
[en] The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect
- Affected:
- up to 2.20.29
- Fixed in:
- 2.20.29
- Disclosed:
- Nov 20, 2023
CVE-2023-5610 on NVD →
Seraphinite Accelerator [seraphinite-accelerator] < 2.20.29
unknown
[en] The Seraphinite Accelerator WordPress plugin before 2.2.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 2.20.29
- Fixed in:
- 2.20.29
- Disclosed:
- Nov 20, 2023
CVE-2023-5609 on NVD →
Seraphinite Accelerator (Base, cache only) <= 2.20.31 - Cross-Site Request Forgery
medium
The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.20.31. This is due to missing nonce validation on the 'reset' case of the Init() function, the 'settImport' case of the _on_admin_action_act() function, and the OnInitAdminMode() function...
- CVSS:
- 4.3
- Affected:
- up to 2.20.31
- Fixed in:
- 2.20.32
- Disclosed:
- Oct 29, 2023
CVE-2023-5611 on NVD →
Seraphinite Accelerator [seraphinite-accelerator] < 2.20.32
unknown
The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.20.31. This is due to missing nonce validation on the 'reset' case of the Init() function, the 'settImport' case of the _on_admin_action_act() function, and the OnInitAdminMode() function...
- Affected:
- up to 2.20.32
- Fixed in:
- 2.20.32
- Disclosed:
- Oct 29, 2023
Seraphinite Accelerator [seraphinite-accelerator] < 2.20.32
unknown
Update the WordPress Seraphinite Accelerator plugin to the latest available version (at least 2.20.32).
An unknown person discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Seraphinite Accelerator Plugin. This could allow a malicious actor to force higher privileged users to execu...
- Affected:
- up to 2.20.32
- Fixed in:
- 2.20.32
- Disclosed:
- Oct 29, 2023
Seraphinite Accelerator <= 2.20.28 - Reflected Cross-Site Scripting via 'rt'
medium
The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rt' parameter in all versions up to, and including, 2.20.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 2.20.28
- Fixed in:
- 2.20.29
- Disclosed:
- Oct 27, 2023
CVE-2023-5609 on NVD →
Seraphinite Accelerator <= 2.20.28 - Arbitrary Redirect via 'redir'
medium
The Seraphinite Accelerator plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.20.28. This is due to insufficient validation on the redirect url supplied via the 'redir' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious si...
- CVSS:
- 5.4
- Affected:
- up to 2.20.28
- Fixed in:
- 2.20.29
- Disclosed:
- Oct 27, 2023
CVE-2023-5610 on NVD →
Seraphinite Accelerator [seraphinite-accelerator] < 2.22.16
unknown
- Affected:
- up to 2.22.16
- Fixed in:
- 2.22.16
CVE-2024-54222 on NVD →
Seraphinite Accelerator [seraphinite-accelerator] < 2.27.22
unknown
The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing or incorrect nonce validation on the 'OnAdminApi_CacheOpBegin' function. This makes it possible for unauthenticated attackers to perform several ad...
- Affected:
- up to 2.27.22
- Fixed in:
- 2.27.22
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database