WP Rocket <= 3.21.0.1 - Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpoint
high
The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input sanitization and output escaping of user-supplied data via the rocket_beacon AJAX endpoint. This makes it possible for unauthenticated attackers to inject arbitra...
- CVSS:
- 7.2
- Affected:
- up to 3.21.0.1
- Fixed in:
- 3.21.1
- Disclosed:
- Aug 27, 2026
CVE-2026-5934 on NVD →
Rocket <= 3.19.4 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.19.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will exe...
- CVSS:
- 6.4
- Affected:
- up to 3.19.4
- Fixed in:
- 3.20.0.2
- Disclosed:
- Oct 20, 2025
CVE-2026-28044 on NVD →
WP Rocket <= 2.10.3 - Local File Inclusion
high
In the WP Rocket plugin 2.10.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypassed by using 0x00 bytes, as demonstrated by a .%00.../.%00.../ attack.
- CVSS:
- 7.5
- Affected:
- up to 2.10.4
- Fixed in:
- 2.10.4
- Disclosed:
- Jun 22, 2017
CVE-2017-11658 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database