CVE-2026-17532 is a reflected cross-site scripting vulnerability in the Seraphinite Accelerator plugin for WordPress affecting versions up to and including 2.29.15. The issue arises from a flawed validation path in the CacheExtractPreparePageParams() function, which uses PHP loose comparison semantics when checking an expected HMAC value against a JSON-decoded nonce value. By supplying the nonce as the JSON boolean true, an attacker can bypass the intended signature verification because a non-empty HMAC string may compare as loosely equal under PHP type juggling rules. This bypass is compounded by insufficient output escaping in the _CbContentFinishSkip() function, which inserts attacker-controlled data from the selfTest field directly into the HTML response body. Together, these flaws allow unauthenticated attackers to cause arbitrary script content to be reflected in a victim's browser.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This four-file repository is a Dockerized proof-of-concept lab for CVE-2026-17532, described as an unauthenticated reflected XSS in Seraphinite Accelerator. docker-compose.yml provisions MySQL 8, WordPress, and a one-shot wpcli installer. The installer deploys and activates Seraphinite Accelerator 2.29.15, enables its cache settings, and ensures an inactive hello.php plugin file exists. exploit.sh is the primary launcher: it reads xss.js, wraps it in a script tag, places it in the selfTest field of a JSON object, Base64-encodes the JSON, URL-encodes it, and prints a target URL using the seraph_accel_prep parameter. xss.js is the post-XSS stage. It runs in the administrator's browser context, fetches the plugin editor page to extract its anti-CSRF nonce, then posts to WordPress admin-ajax.php with edit-theme-plugin-file to replace hello.php. The replacement is a PHP web shell that executes a supplied c parameter using shell_exec and renders output in a browser form. No external attacker infrastructure is required because the JavaScript is fully embedded in the crafted URL. The code is an operational, hardcoded lab exploit rather than a detection-only script or a framework module.
Repository contains a small, focused exploit set for CVE-2026-17532 affecting the WordPress Seraphinite Accelerator plugin <= 2.29.18. Structure: a README describing the bug and usage, a standalone Python exploit script, and a Nuclei template. The vulnerability is an unauthenticated reflected XSS caused by weak validation of the seraph_accel_prep parameter: the plugin expects a signed base64-encoded JSON blob but compares the nonce/HMAC value with PHP loose inequality, allowing JSON boolean true to bypass validation. The attacker controls the selfTest field, which is reflected into the response as selfTest-<value> without escaping. The Python script builds the malicious JSON object ({"_tm":"1","nonce":true,"selfTest":payload}), base64-encodes it, URL-encodes it into /?seraph_accel_prep=..., sends a GET request, and checks whether the payload is reflected in a 200 OK response. The default payload is a benign JavaScript alert, but the script accepts arbitrary attacker-supplied XSS payloads. The Nuclei template performs the same single-request check and matches on reflected script content, text/html headers, and HTTP 200. Overall, this is a real operational PoC for reflected browser-side code execution, not RCE; it is intended for validation and exploitation via crafted links against vulnerable public WordPress sites.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.