← Terug naar overzicht

The WP Rocket plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability affecting versions up to and including 3.21.0.1. The vulnerability stems from insufficient input sanitization and output escaping of user-supplied data via the rocket_beacon AJAX endpoint. Unauthenticated attackers can exploit this flaw to inject arbitrary web scripts into pages. These injected scripts execute whenever any user accesses the compromised page, posing a broad risk to site visitors. The vulnerability requires no authentication, significantly lowering the barrier for exploitation. A fix was released in version 3.21.1 of the WP Rocket plugin. The issue has been documented by both NVD and Wordfence threat intelligence. WordPress site administrators running affected versions should update immediately to mitigate risk.

Affected products

  • WP Rocket plugin for WordPress 3.21.0.1 and below

Related CVE's

  • CVE-2026-5934

Categories

  • Web Technologies