{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awp-rocketwp-rocketwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wp-rocket:wp-rocket:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-5934"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Rocket (\u003c= 3.21.0.1)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress","vulnerability"],"_cs_type":"advisory","_cs_vendors":["WP Rocket"],"content_html":"\u003cp\u003eThe WP Rocket plugin for WordPress, in versions up to and including 3.21.0.1, contains a critical Stored Cross-Site Scripting (XSS) vulnerability identified as CVE-2026-5934. The flaw originates from insufficient input sanitization and output escaping mechanisms within the 'rocket_beacon' AJAX endpoint. This vulnerability allows unauthenticated attackers to inject arbitrary malicious web scripts into the plugin's data handling processes. When a user - typically an administrator - accesses the page where the injected script is stored, the browser executes the malicious code. This could lead to session hijacking, unauthorized administrative actions, or persistent defacement of the affected WordPress instance. Defenders should prioritize updating to the latest version to mitigate this injection vector.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session. This poses a significant risk to WordPress site integrity, potentially allowing attackers to steal session cookies, perform unauthorized configuration changes, or redirect traffic. The vulnerability impacts all WordPress sites running vulnerable versions of the WP Rocket plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the WP Rocket plugin to the version that includes the patch for CVE-2026-5934.\u003c/li\u003e\n\u003cli\u003eImplement a strict Content Security Policy (CSP) to mitigate the impact of unauthorized script execution.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious requests targeting the 'rocket_beacon' AJAX endpoint.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-28T17:13:38Z","date_published":"2026-08-28T17:13:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wp-rocket-xss/","summary":"WP Rocket versions up to and including 3.21.0.1 are vulnerable to unauthenticated Stored Cross-Site Scripting via the rocket_beacon AJAX endpoint.","title":"Stored Cross-Site Scripting Vulnerability in WP Rocket","url":"https://feed.craftedsignal.io/briefs/2026-08-wp-rocket-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wp-Rocket:wp-Rocket:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}