Sceawere
Vulnerability Detail
CVE-2026-97075UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Rocket Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- WP Media
- Product
- WP Rocket
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Missing Authorization vulnerability in WP Media WP Rocket wp-rocket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Rocket: from n/a before 3.23.5.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-09T08:16:55.683Z",
"pubdate": "2026-10-09T08:16:55.683Z",
"executiveSummary": "A missing authorization vulnerability has been identified in the WP Rocket plugin for WordPress, specifically concerning the handling of access control security levels.\nThe vulnerability allows unauthorized users to perform actions restricted by access control configurations, potentially leading to unauthorized system manipulation or information disclosure.\nThis issue affects all versions of WP Rocket prior to 3.23.5.\nThe flaw stems from improper implementation of authorization checks within the plugin's internal logic, allowing an attacker to bypass intended security constraints.\nSuccessful exploitation requires the attacker to identify accessible endpoints that fail to properly validate the user's authorization level before executing sensitive functionality.\nThe security impact is significant, as it permits authenticated or potentially unauthenticated actors to interact with restricted features, compromising the integrity of the plugin's configuration and the underlying site's performance settings.",
"technicalDetails": "The core of the vulnerability resides in the insufficient enforcement of access control mechanisms within the WP Rocket codebase. Specifically, the affected functions or endpoints fail to adequately verify the permissions of the calling user before executing sensitive administrative or configuration-related operations.\nWhen a user interacts with the affected component, the application fails to perform a rigorous check against the WP_USER or appropriate capability-based access control list (ACL). Consequently, if an attacker invokes these endpoints, the plugin processes the request as if it originated from an authorized administrator, bypassing the necessary security gatekeepers.\nThe attack flow typically involves the attacker crafting a request directed at the vulnerable component. By manipulating the request parameters—or simply invoking a restricted function call directly through the plugin's API interface—the attacker triggers actions that should be restricted to users with higher privilege levels, such as 'administrator' or specific plugin management roles.\nThis exploitation does not require advanced injection techniques; rather, it relies on the absence of proper authentication and authorization checks at the functional entry point. Once the request reaches the vulnerable component, the lack of a secondary validation step allows the execution of backend logic that modifies site cache settings, database entries, or other critical operational parameters.\nThe technical impact is severe due to the potential for unauthorized alteration of the site's optimization settings, which could lead to service degradation or the inadvertent exposure of cached data. Because the plugin manages complex performance-related tasks, unauthorized execution can result in the manipulation of files or databases associated with WP Rocket's operations.\nAffected versions from n/a to 3.23.4 are susceptible to this authorization bypass. The vulnerability highlights a failure in secure coding practices regarding API endpoint protection and privilege verification within WordPress plugin development. Administrators should note that while this is categorized as a missing authorization issue, its exploitation is straightforward once the specific endpoint paths are identified, making immediate remediation essential to maintaining the security posture of the WordPress environment."
}