Missing Authorization Vulnerability in RockPress Plugin for WordPress
CVE-2026-3550

5.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-3550?

The RockPress plugin for WordPress suffers from a Missing Authorization vulnerability affecting all versions up to and including 1.0.17. This security flaw arises from a lack of capability checks across several AJAX actions, such as rockpress_import and rockpress_reset_import. Additionally, the plugin exposes its nonce to all authenticated users through a universally enqueued admin script, enabling authenticated users, including those with Subscriber-level access, to exploit the vulnerability. By extracting the nonce from any admin page’s HTML, these users can trigger critical operations including imports, resets of import data, and service connectivity checks, actions that are intended to be restricted to administrators.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

RockPress * <= 1.0.17

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phong Nguyen
.