CVE-2026-28044: WordPress WP Rocket plugin <= 3.19.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket allows Stored XSS.This issue affects WP Rocket: from n/a through 3.19.4.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket wp-rocket allows Stored XSS.This issue affects WP Rocket: from n/a through <= 3.19.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28044?
CVE-2026-28044 has been rated as a critical severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2026-28044?
To fix CVE-2026-28044, upgrade the WP Rocket plugin to version 3.19.5 or later.
What type of attack does CVE-2026-28044 facilitate?
CVE-2026-28044 facilitates stored cross-site scripting (XSS) attacks, allowing an attacker to inject malicious scripts.
Which versions of WP Rocket are affected by CVE-2026-28044?
CVE-2026-28044 affects WP Rocket versions up to and including 3.19.4.
Is any user data at risk due to CVE-2026-28044?
Yes, user data is at risk due to the possibility of malicious scripts being executed in the context of the user’s browser.