๐Ÿ”’WP Rocket Security Issues

Minor Issue WordPress WP Rocket
August 28, 2026 08:27 AM PDT ยท 14 hours, 23 minutes

Updates

Monitoring

WP Rocket had a couple of a security issues reported publicly today. Both issues have been addressed and patched by our team and tools. ๐Ÿ˜ฎโ€๐Ÿ’จ

Data exposure issue

One issue could have exposed account email addresses, license keys, and โ€” on sites where those integrations are set up โ€” Cloudflare and Sucuri API keys. Though most sites are using our WP Rocket license, some still had old data stored in the database.

WP Rocket released a patch for the vulnerability shortly after notified and there have been no reports of any data being exposed.

As soon as we were notified, our team added a security rule to Cloudflare Enterprise to virtually patch the issue and weโ€™re updating WP Rocket, prioritizing sites that had stored data.

XSS Vulnerability (previously patched)

Additionally, a medium priority Cross Site Scripting (XSS) vulnerability was reported. XSS vulnerabilities allow bad actors to inject malicious scripts into sites that are executed when a guest visits the site. This vulnerability required a privileged user role to carry out the attack.

This vulnerability was patched in an April plugin release, so most of our sites were already protected through regular updates. However for sites not yet on a secure version (3.21.1), one of our security services has already released a security patch to protect those sites as well.

August 28, 2026 ยท 08:27 AM PDT

โ† Back