Impact
A state‑update AJAX action in the Seraphinite Accelerator WordPress plugin prior to version 2.29.24 lacks a capability check, allowing any authenticated subscriber to submit a malformed value. The error that is triggered on every subsequent admin page load renders the entire WordPress admin area unusable, effectively denying administrators access to manage the site. The flaw is a failure to validate user permissions, resulting in a denial‑of‑service condition for privileged users.
Affected Systems
The vulnerability affects the Seraphinite Accelerator WordPress plugin for all releases earlier than 2.29.24. Users of newer versions are not impacted.
Risk and Exploitability
Although the EPSS score indicates a very low probability of exploitation (<1%) and the issue is not listed in the CISA KEV catalog, any subscriber with access can trigger the exploit. The lack of a privilege check means the flaw can be introduced by a non‑admin actor, while the denial of service impacts the availability of administrative functions. The vulnerability scores on CVSS (where available) would be high given the direct impact on availability, but the low EPSS and absence from KEV suggest that the immediate threat level is moderate in the absence of targeted exploitation.
OpenCVE Enrichment