Missing Authorization Vulnerability in RockPress Plugin for WordPress
CVE-2026-3550
What is CVE-2026-3550?
The RockPress plugin for WordPress suffers from a Missing Authorization vulnerability affecting all versions up to and including 1.0.17. This security flaw arises from a lack of capability checks across several AJAX actions, such as rockpress_import and rockpress_reset_import. Additionally, the plugin exposes its nonce to all authenticated users through a universally enqueued admin script, enabling authenticated users, including those with Subscriber-level access, to exploit the vulnerability. By extracting the nonce from any admin page’s HTML, these users can trigger critical operations including imports, resets of import data, and service connectivity checks, actions that are intended to be restricted to administrators.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
RockPress * <= 1.0.17
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved