plugin

Rock Convert Vulnerabilities

8 known security issues reported for the Rock Convert WordPress plugin. Most recent disclosed Oct 27, 2025.

4 medium

Running Rock Convert on your site? Check whether your installed version is affected.

Scan your site free

Rock Convert [rock-convert] <= 3.0.1 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Content Rock Convert rock-convert allows Stored XSS.This issue affects Rock Convert: from n/a through <= 3.0.1.

Affected:
up to 3.0.1
Fix:
No patched version reported
Disclosed:
Oct 27, 2025

CVE-2025-62911 on NVD →

Rock Convert <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Rock Convert plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...

CVSS:
6.4
Affected:
up to 3.0.1
Fix:
No patched version reported
Disclosed:
Sep 30, 2025

CVE-2025-62911 on NVD →

Rock Convert [rock-convert] < 3.0.0

unknown

[en] Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress.

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Nov 3, 2022

CVE-2022-36428 on NVD →

Rock Convert [rock-convert] < 2.11.0

unknown

[en] The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.11.0
Fixed in:
2.11.0
Disclosed:
Oct 31, 2022

CVE-2022-3440 on NVD →

Rock Convert [rock-convert] < 2.11.0

unknown

[en] The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 2.11.0
Fixed in:
2.11.0
Disclosed:
Oct 31, 2022

CVE-2022-3441 on NVD →

Rock Convert <= 2.10.2 - Reflected Cross-Site Scripting

medium

The Rock Convert plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping on the URL. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can suc...

CVSS:
6.1
Affected:
up to 2.10.2
Fixed in:
2.11.0
Disclosed:
Oct 10, 2022

CVE-2022-3440 on NVD →

Rock Convert <= 2.10.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Rock Convert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text’ field on the settings form in versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...

CVSS:
5.5
Affected:
up to 2.10.2
Fixed in:
2.11.0
Disclosed:
Oct 10, 2022

CVE-2022-3441 on NVD →

Rock Convert <= 2.11.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Rock Convert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's settings such as the 'rock_convert_popup_title' parameter in versions up to, and including, 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

CVSS:
5.5
Affected:
up to 2.11.0
Fixed in:
3.0.0
Disclosed:
Oct 4, 2022

CVE-2022-36428 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database