PT-2026-22902 · WordPress · Seraphinite Accelerator

Lukasz Sobanski

·

Publicado

2026-03-04

·

Atualizado

2026-03-04

·

CVE-2026-3058

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Seraphinite Accelerator plugin for WordPress versions up to and including 2.28.14
Description The Seraphinite Accelerator plugin for WordPress is susceptible to sensitive information disclosure. This is due to the OnAdminApi GetData() function lacking proper capability checks. Authenticated attackers with Subscriber-level access or higher can retrieve sensitive operational data through the seraph accel api AJAX action with the fn=GetData parameter. This data includes cache status, scheduled task information, and external database state. The GetData parameter is used in the seraph accel api API endpoint.
Recommendations Update the Seraphinite Accelerator plugin to a version later than 2.28.14.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3058

Produtos afetados

Seraphinite Accelerator