๐WP Rocket Security Issues
Updates
WP Rocket had a couple of a security issues reported publicly today. Both issues have been addressed and patched by our team and tools. ๐ฎโ๐จ
Data exposure issue
One issue could have exposed account email addresses, license keys, and โ on sites where those integrations are set up โ Cloudflare and Sucuri API keys. Though most sites are using our WP Rocket license, some still had old data stored in the database.
WP Rocket released a patch for the vulnerability shortly after notified and there have been no reports of any data being exposed.
As soon as we were notified, our team added a security rule to Cloudflare Enterprise to virtually patch the issue and weโre updating WP Rocket, prioritizing sites that had stored data.
XSS Vulnerability (previously patched)
Additionally, a medium priority Cross Site Scripting (XSS) vulnerability was reported. XSS vulnerabilities allow bad actors to inject malicious scripts into sites that are executed when a guest visits the site. This vulnerability required a privileged user role to carry out the attack.
This vulnerability was patched in an April plugin release, so most of our sites were already protected through regular updates. However for sites not yet on a secure version (3.21.1), one of our security services has already released a security patch to protect those sites as well.
โ Back
NerdPress Issue Updates