Executive brief
WP Rocket is a widely-used WordPress caching and performance optimization plugin installed on hundreds of thousands of websites. A flaw in the rocket_beacon AJAX endpoint allows unauthenticated attackers to inject malicious JavaScript that persists in the database and executes when any user visits an affected page, enabling credential theft, malware distribution, or account hijacking without requiring any user interaction beyond visiting the site.
Technical details
The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the rocket_beacon AJAX endpoint of WP Rocket versions up to 3.21.0.1. The root cause is insufficient input sanitization and output escaping of user-supplied data submitted to this endpoint. Because the endpoint is accessible to unauthenticated users and the malicious payload is stored in the database, any subsequent visitor to an affected page will execute the injected script in their browser context. The vulnerability was patched in version 3.21.1. The attack requires no authentication, user interaction, or special preconditions beyond the plugin being installed and active.
Affected products
- WP Media WP Rocket up to 3.21.0.1
Timeline
- 2026-08-28: disclosed
- 2026-04-07: patched: Version 3.21.1 released