{"error":0,"message":null,"data":{"name":"WP Rocket","plugin":"wp-rocket","link":null,"latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"bb9469564a9bb64475e8f9744ec821f42d3909770769232f5f6fb22df8f1ac3f","name":"WP Rocket [wp-rocket] < 2.10.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-11658","name":"CVE-2017-11658","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-11658","description":"[en] In the WP Rocket plugin 2.9.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypassed by using 0x00 bytes, as demonstrated by a .%00...\/.%00...\/ attack.","date":"2017-07-26"},{"id":"c52c99ba6acb1adeca3813ec7a60ca5c7a8a7612","name":"WP Rocket <= 2.10.3 - Local File Inclusion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-rocket\/wp-rocket-2103-local-file-inclusion","description":"In the WP Rocket plugin 2.10.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypassed by using 0x00 bytes, as demonstrated by a .%00...\/.%00...\/ attack.","date":"2017-06-22"},{"id":"5484d821-7017-47a8-90d8-7d87cb5e0e50","name":"WP Rocket &lt;= 2.10.3 - Local File Inclusion (LFI)","link":"https:\/\/wpscan.com\/vulnerability\/5484d821-7017-47a8-90d8-7d87cb5e0e50","description":"Requires older versions of PHP that are vulnerable to null byte injection.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"3ad5db4857fea15c0765079329d0eb15be4643aaac1cf7ea2b5b30c782483112","name":"WP Rocket [wp-rocket] < 2.10.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.10.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ae24cc94d8edf12fd37710b5c83939f2eb89b73e","name":"WordPress WP Rocket plugin <=2.10.3 - Local File Inclusion (LFI) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-rocket\/vulnerability\/wordpress-wp-rocket-plugin-2-10-3-local-file-inclusion-lfi-vulnerability","description":"Local File Inclusion (LFI) vulnerability discovered by Paulos Yibelo in WordPress WP Rocket plugin 2.10.3 and earlier versions. Requires an older (deprecated) PHP version that is vulnerable to null byte injection.\nUpdate WordPress WP Rocket plugin to the latest available version (at least 2.10.4).","date":"2017-07-28"}],"impact":[]},{"uuid":"8fd24cf82b859873054673eab32181358888ce7da49d4aa04ff4e8933325a9f8","name":"WP Rocket [wp-rocket] < 3.20.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.20.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-28044","name":"CVE-2026-28044","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-28044","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket allows Stored XSS.This issue affects WP Rocket: from n\/a through 3.19.4.","date":"2026-03-19"},{"id":"3ee328d17588a2098f6fac16af8935dde6d40a29","name":"Rocket <= 3.19.4 - Authenticated (Author+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-rocket\/rocket-3194-authenticated-author-stored-cross-site-scripting","description":"The Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.19.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-10-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"1.7","impact":"3.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"1.7","impact":"3.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7cfd703597ac12caefab234682a5df83588147ff7fbf31ffbf808dc5f573f58a","name":"WP Rocket [wp-rocket] < 3.21.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.21.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5934","name":"CVE-2026-5934","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5934","description":"[en] The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input sanitization and output escaping of user-supplied data via the rocket_beacon AJAX endpoint. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-08-28"},{"id":"ef78f59e9dd6a9153862ee75d659db5a3c01badd","name":"WP Rocket <= 3.21.0.1 - Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpoint","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-rocket\/wp-rocket-32101-unauthenticated-stored-cross-site-scripting-via-picture-source-attributes-in-rocket-beacon-endpoint","description":"The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input sanitization and output escaping of user-supplied data via the rocket_beacon AJAX endpoint. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-10-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a5c73b8e2e5833deb594b08d8c62bd33bd595c054395be55f4efcfd38fb98a72","name":"WP Rocket [wp-rocket] >= 3.23.1 - < 3.23.3.3","description":null,"operator":{"min_version":"3.23.1","min_operator":"ge","max_version":"3.23.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1281c722420c048668b9023eaa2fa2375e61f8f4","name":"WordPress WP Rocket Plugin 3.23.1-3.23.3.2 is vulnerable to a medium priority Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-rocket\/vulnerability\/wordpress-wp-rocket-plugin-3-23-1-3-23-3-2-unauthenticated-sensitive-data-exposure-vulnerability","description":"<p>WordPress WP Rocket Plugin 3.23.1-3.23.3.2 is vulnerable to a medium priority Sensitive Data Exposure<\/p><p>Software: WP Rocket<\/p><p>Link: https:\/\/github.com\/wp-media\/wp-rocket<\/p><p>Fixed in version 3.23.3.3 <\/p><p>Affected Version 3.23.1-3.23.3.2<\/p><p>CVE: Unknown<\/p>","date":"2026-08-28"}],"impact":[]},{"uuid":"908926c3f5d2aa38776a804cfdb43b4a5e38613069f0c31e2438c22729d9fedb","name":"WP Rocket [wp-rocket] < 3.23.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.23.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"14c6d024160544d8a47aa99a878de44bb78196d1","name":"WP Rocket 3.23.1 - 3.23.3.2 - Unauthenticated Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-rocket\/wp-rocket-3231-32332-unauthenticated-information-exposure","description":"The WP Rocket plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 3.23.1 through 3.23.3.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2026-08-27"}],"impact":[]}]},"updated":"1788419973"}