<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WP Rocket - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/wp-rocket/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 28 Aug 2026 17:13:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/wp-rocket/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting Vulnerability in WP Rocket</title><link>https://feed.craftedsignal.io/briefs/2026-08-wp-rocket-xss/</link><pubDate>Fri, 28 Aug 2026 17:13:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-wp-rocket-xss/</guid><description>WP Rocket versions up to and including 3.21.0.1 are vulnerable to unauthenticated Stored Cross-Site Scripting via the rocket_beacon AJAX endpoint.</description><content:encoded><![CDATA[<p>The WP Rocket plugin for WordPress, in versions up to and including 3.21.0.1, contains a critical Stored Cross-Site Scripting (XSS) vulnerability identified as CVE-2026-5934. The flaw originates from insufficient input sanitization and output escaping mechanisms within the 'rocket_beacon' AJAX endpoint. This vulnerability allows unauthenticated attackers to inject arbitrary malicious web scripts into the plugin's data handling processes. When a user - typically an administrator - accesses the page where the injected script is stored, the browser executes the malicious code. This could lead to session hijacking, unauthorized administrative actions, or persistent defacement of the affected WordPress instance. Defenders should prioritize updating to the latest version to mitigate this injection vector.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session. This poses a significant risk to WordPress site integrity, potentially allowing attackers to steal session cookies, perform unauthorized configuration changes, or redirect traffic. The vulnerability impacts all WordPress sites running vulnerable versions of the WP Rocket plugin.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the WP Rocket plugin to the version that includes the patch for CVE-2026-5934.</li>
<li>Implement a strict Content Security Policy (CSP) to mitigate the impact of unauthorized script execution.</li>
<li>Monitor web server logs for suspicious requests targeting the 'rocket_beacon' AJAX endpoint.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>wordpress</category><category>vulnerability</category></item></channel></rss>