← Back to overview

The WP Rocket plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability affecting versions up to and including 3.21.0.1. The vulnerability stems from insufficient input sanitization and output escaping of user-supplied data via the rocket_beacon AJAX endpoint. Unauthenticated attackers can exploit this flaw to inject arbitrary web scripts into pages. These injected scripts execute automatically whenever any user accesses the affected page. The vulnerability poses a significant risk due to its unauthenticated nature, allowing widespread exploitation without requiring any credentials. A patch was released in version 3.21.1. The issue is tracked under CVE-2026-5934 and has been documented by both NVD and Wordfence.

Affected products

  • WP Rocket plugin for WordPress
  • WordPress

Related CVE's

  • CVE-2026-5934

Categories

  • Web Technologies