Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.7 WordPress CVE-2026-97076 CVE-2026-97075

WP Rocket: CVE-2026-97076 and CVE-2026-97075

Two vulnerabilities in the WP Rocket WordPress plugin allow (1) code-injection via an executable regular-expression error (CVE-2026-97076) and (2) missing authorization that permits incorrect access (CVE-2026-97075). Both are reported fixed at 3.23.5 in source data, but fix availability is inconsistent in the advisory metadata. [Sources: 4791, 32082, 4790, 32092]

Synthesized by AI from 4 sources · updated 1 hour ago

AI summary

This briefing summarizes two recently published vulnerabilities affecting the WP Rocket WordPress plugin (wp-rocket). The records list CVE-2026-97076 (executable regular expression leading to possible code injection) and CVE-2026-97075 (missing authorization / incorrect access control). Source data indicate a fixed version of 3.23.5, but fix availability is not consistently reported; see the editorial warnings below. [Sources: 4791, 32082, 4790, 32092]

What happened

Two vulnerabilities were published for the WP Rocket plugin: CVE-2026-97076 is described as an executable regular-expression error that can allow code injection; CVE-2026-97075 is described as a missing-authorization issue that allows bypassing intended access controls. These descriptions come from the published advisory records. [Sources: 4791, 32082, 4790, 32092]

Technical cause

The advisories classify the issues under CWEs: CVE-2026-97076 is associated with CWE-624 (executable regular expression error) and CVE-2026-97075 with CWE-862 (missing authorization / improper access control). The published records provide these classifications. [Sources: 4791, 32082, 4790, 32092]

Why it matters

Both issues are reachable over the network without authentication and require no user interaction according to the advisory metadata. CVE-2026-97076 has a CVSS v3.1 base score of 7.5 (vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicating a high impact on availability. CVE-2026-97075 has a CVSS v3.1 base score of 6.5 (vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N) indicating low-to-moderate impact to confidentiality and integrity. The advisory records report there is no known public exploit and no known active exploitation. [Sources: 4791, 32082, 4790, 32092]

Who is affected

The advisories identify the product WP Rocket (package name: wp-rocket) as affected. Source records list the affected range as versions prior to 3.23.5. Use the plugin package metadata on your sites to determine if your installation is older than the fixed release referenced in the sources. [Sources: 4791, 32082, 4790, 32092]

Discovery and timeline

The advisories were published on 2026-10-09. The relevant source records are listed in the advisory package and NVD entries referenced in the source data. The advisories include modified timestamps in their metadata. See source items for original records. [Sources: 4791, 32082, 4790, 32092]

Affected versions

Source records indicate the issues affect WP Rocket releases before 3.23.5; the package metadata and claim entries list a fix event at 3.23.5. The advisories' structured data identify 3.23.5 as the fixed version. [Sources: 4791, 32082, 4790, 32092]

Fixes and mitigation

Package entries and affected-range claims in the source data list a fix event at version 3.23.5. However, the advisory metadata field 'fix_available' is set to false in both advisory records, creating an inconsistency in the source package. We cannot confirm from the provided data whether an update is published and distributed or whether the fix is otherwise available. [Sources: 4791, 32082, 4790, 32092]

Recommended action

Check your WP Rocket installations and the plugin update channel for the vendor update referenced as 3.23.5. If your installations are older than the fixed release reported in the sources, apply the vendor update 3.23.5 when it is confirmed available. Because the advisory metadata is inconsistent about fix availability, verify the update’s presence from the vendor or trusted distribution channels before deploying. [Sources: 4791, 32082, 4790, 32092]

PatchBriefing score

5.7 / 10 · Medium

Official CVSS: 7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Why this score

The two records carry CVSS v3.1 base scores of 7.5 and 6.5 as published in the advisories. CVE-2026-97076 (7.5) is scored for a high impact on availability (A:H) with no required privileges or user interaction. CVE-2026-97075 (6.5) scores lower and primarily affects confidentiality and integrity to a limited degree (C:L/I:L) while also requiring no privileges or user interaction. These published CVSS values are used without modification. [Sources: 4791, 32082, 4790, 32092]

Affected versions

WP Rocket < 3.23.5
vulnerable
WP Rocket < 3.23.5
vulnerable

Reported fixes

Package entries and affected-range claims in the source data list a fix event at version 3.23.5. However, the advisory metadata field 'fix_available' is set to false in both advisory records, creating an inconsistency in the source package. We cannot confirm from the provided data whether an update is published and distributed or whether the fix is otherwise available. [Sources: 4791, 32082, 4790, 32092]

How this was built

4 source records were collected, matched and used to prepare the report above.

  • WPVulnerability database
  • NVD (NIST) database
  • WPVulnerability database
  • NVD (NIST) database
Unified report
WP Rocket: CVE-2026-97076 and CVE-2026-97075
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email