Stored Cross-Site Scripting in WP Rocket Plugin by WP Media
CVE-2026-5934
7.2HIGH
What is CVE-2026-5934?
The WP Rocket plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability when using versions up to and including 3.21.0.1. This flaw stems from improper input sanitization and output escaping of user-generated data via the rocket_beacon AJAX endpoint. Attackers can exploit this vulnerability to inject unauthorized web scripts into pages that will execute when a user visits the compromised page, potentially leading to unauthorized actions and data theft.
Affected Version(s)
WP Rocket 0 <= 3.21.0.1