Sceawere

Vulnerability Detail

CVE-2026-97076UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Rocket Executable Regex Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
WP Media
Product
WP Rocket
Attack Type
Executable Regular Expression Error
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Executable Regular Expression Error vulnerability in WP Media WP Rocket wp-rocket allows Code Injection.This issue affects WP Rocket: from n/a before 3.23.5.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-09T07:17:19.350Z",
  "pubdate": "2026-10-09T07:17:19.350Z",
  "executiveSummary": "A critical vulnerability categorized as Executable Regular Expression Error exists within the WP Rocket WordPress plugin, facilitating arbitrary Code Injection.\nThis security flaw impacts all versions of WP Rocket prior to 3.23.5.\nThe vulnerability poses a severe risk to WordPress installations, as it allows unauthenticated or unauthorized attackers to manipulate regex processing logic to achieve remote code execution (RCE) or perform other malicious actions on the host server.\nThe core issue stems from the improper handling of regular expressions, which can be leveraged to alter application behavior or execute arbitrary PHP code through input manipulation.\nThe impact is significant, potentially leading to full site compromise, unauthorized data access, and persistence mechanism installation.\nMitigation requires an immediate update to the patched version, as the flaw resides within the internal plugin logic utilized during request processing or administrative configurations.",
  "technicalDetails": "The vulnerability identified in WP Rocket is an Executable Regular Expression Error that permits Code Injection. This class of vulnerability occurs when user-supplied data or improperly sanitized strings are interpreted as part of a regular expression pattern that is subsequently evaluated by the PHP engine or internal plugin components.\nIn the context of WP Rocket, which manages heavy caching and optimization routines, regular expressions are frequently used to match URLs, file paths, or browser agent strings for performance filtering.\nThe root cause is the unsafe incorporation of external input into regex delimiters or pattern structures. When the input is not strictly validated, an attacker can supply crafted payloads containing regex modifiers—specifically the 'e' (PREG_REPLACE_EVAL) modifier, if supported, or other pattern-based injections that force the application to treat processed strings as executable code.\nThe attack flow typically follows this sequence: 1. An attacker identifies an input vector handled by the plugin that influences regex generation. 2. The attacker injects a malicious payload designed to break out of the intended regex pattern. 3. Because the vulnerable component processes the string in a context where it is later evaluated, the crafted payload is parsed and executed by the underlying server environment. This essentially bridges the gap between a static pattern match and a dynamic code execution context.\nAffected versions include all releases from the inception of the affected component up to, but not including, version 3.23.5. Because this logic is often embedded in core optimization functions, the vulnerability can be triggered during standard page requests or administrative operations, depending on where the regex is evaluated.\nThe post-exploitation impact includes the execution of arbitrary PHP instructions with the privileges of the web server user. This allows attackers to bypass security boundaries, modify site content, exfiltrate sensitive database information, or gain persistence by injecting backdoors into the WordPress file system. Given the nature of WordPress plugins, such an exploit provides a high-level entry point into the application architecture."
}
CVE-2026-97076: WP Rocket Executable Regex Injection (HIGH Severity, CVSS: 7.5) | Sceawere