Unrated severityNVD Advisory· Published Sep 16, 2026
CVE-2026-87828
CVE-2026-87828
Description
The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscribers to write a malformed value that causes an uncaught error on every subsequent admin page load, making the entire admin area inaccessible to all administrators (denial of service).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.29.24
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.