Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pwq8-qxp8-42qc

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscribers to write a malformed value that causes an uncaught error on every subsequent admin page load, making the entire admin area inaccessible to all administrators (denial of service).

The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscribers to write a malformed value that causes an uncaught error on every subsequent admin page load, making the entire admin area inaccessible to all administrators (denial of service).

EPSS

Процентиль: 16%
0.00242
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.7
nvd
8 дней назад

The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscribers to write a malformed value that causes an uncaught error on every subsequent admin page load, making the entire admin area inaccessible to all administrators (denial of service).

EPSS

Процентиль: 16%
0.00242
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-400