VYPR

wp-rocket

by Wp Media

CVEs (1)

  • CVE-2026-5934HigAug 28, 2026
    risk 0.40cvss 7.2epss 0.00

    The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input sanitization and output escaping of user-supplied data via the rocket_beacon AJAX endpoint. This makes it possible for…