PT-2026-22902 · WordPress · Seraphinite Accelerator

Lukasz Sobanski

·

Published

2026-03-04

·

Updated

2026-03-04

·

CVE-2026-3058

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Seraphinite Accelerator plugin for WordPress versions up to and including 2.28.14
Description The Seraphinite Accelerator plugin for WordPress is susceptible to sensitive information disclosure. This is due to the OnAdminApi GetData() function lacking proper capability checks. Authenticated attackers with Subscriber-level access or higher can retrieve sensitive operational data through the seraph accel api AJAX action with the fn=GetData parameter. This data includes cache status, scheduled task information, and external database state. The GetData parameter is used in the seraph accel api API endpoint.
Recommendations Update the Seraphinite Accelerator plugin to a version later than 2.28.14.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-3058

Affected Products

Seraphinite Accelerator