Authorization Flaw in WP Rocket by WP Media
CVE-2026-97075
6.5MEDIUM
What is CVE-2026-97075?
A missing authorization vulnerability exists in the WP Rocket plugin provided by WP Media, which could allow unauthorized users to exploit incorrectly configured access control settings. This issue affects versions of WP Rocket prior to 3.23.5, potentially compromising the security of WordPress sites utilizing this plugin. Users are advised to update to the latest version to mitigate any risks.
Affected Version(s)
WP Rocket 0 < 3.23.5