Impact
The vulnerability is a missing or incorrect nonce check in the OnAdminApi_CacheOpBegin function, enabling a CSRF attack that lets unauthenticated users cause a logged‑in administrator to perform privileged actions like clearing the cache. This can disrupt site performance or logging without granting direct access to content.
Affected Systems
The affected product is the WordPress plugin Seraphinite Accelerator up to and including version 2.27.21, provided by Seraphinite Software. No other versions are mentioned.
Risk and Exploitability
CVSS score 4.3 indicates low severity. EPSS <1% shows a very low probability of exploitation. The flaw is not listed in CISA KEV, suggesting no known widespread exploitation yet. The attack requires a victim administrator to click a crafted link after the attacker lures them; thus it relies on social engineering, and no remote code execution or direct authentication is needed.
OpenCVE Enrichment
EUVD