AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-17532

MEDIUM · CVSS 6.1 EPSS 0.56%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Seraphinite Accelerator plugin for WordPress is vulnerable to reflected cross-site scripting due to improper handling of the 'seraph_accel_prep' parameter, allowing attackers to bypass HMAC signature checks and inject malicious scripts into web pages. This vulnerability can be exploited by unauthenticated attackers to execute arbitrary scripts in the context of a user's session, potentially leading to data theft or further compromise. WordPress site administrators using affected versions should prioritize updating the plugin to mitigate this risk.

CVE
CVE-2026-17532
Severity
MEDIUM
CVSS
6.1
EPSS
0.56%
WordPress

Original NVD Description

The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up to, and including, 2.29.15. This is due to the CacheExtractPreparePageParams() function using PHP's loose inequality operator (!=) to compare the expected HMAC string against the JSON-decoded 'nonce' value — supplying the JSON boolean true causes any non-empty HMAC string to compare as loosely equal, bypassing the signature check — combined with insufficient output escaping in the _CbContentFinishSkip() function, which concatenates the attacker-controlled 'selfTest' field directly into the HTML response body. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.