CVE-2026-17532

MEDIUM

Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-17532. PoCs published by kalhoralireza.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-17532, an unauthenticated reflected XSS vulnerability in Seraphinite Accelerator (WordPress plugin <= 2.29.18). The exploit bypasses HMAC signature checks by sending a JSON boolean `true` as the nonce, which passes PHP's loose comparison, and injects unescaped JavaScript via the `selfTest` parameter.

Description

The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up to, and including, 2.29.15. This is due to the CacheExtractPreparePageParams() function using PHP's loose inequality operator (!=) to compare the expected HMAC string against the JSON-decoded 'nonce' value — supplying the JSON boolean true causes any non-empty HMAC string to compare as loosely equal, bypassing the signature check — combined with insufficient output escaping in the _CbContentFinishSkip() function, which concatenates the attacker-controlled 'selfTest' field directly into the HTML response body. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.

Exploits (1)

nomisec WORKING POC
by kalhoralireza · poc
https://github.com/kalhoralireza/CVE-2026-17532

This repository contains a functional proof-of-concept exploit for CVE-2026-17532, an unauthenticated reflected XSS vulnerability in Seraphinite Accelerator (WordPress plugin <= 2.29.18). The exploit bypasses HMAC signature checks by sending a JSON boolean `true` as the nonce, which passes PHP's loose comparison, and injects unescaped JavaScript via the `selfTest` parameter.

Classification
Working Poc 98%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Seraphinite Accelerator (WordPress plugin) <= 2.29.18
No auth needed
Prerequisites: Plugin's page cache must be enabled · Target must be running a vulnerable version (<= 2.29.18)
mistral-large-3 · analyzed Aug 05, 2026 Full analysis →

Scores

CVSS v3 6.1
EPSS 0.0035
EPSS Percentile 27.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
seraphinitesoft/Seraphinite Accelerator < 2.29.18
Published Aug 05, 2026
Tracked Since Aug 05, 2026