Description
Executable Regular Expression Error vulnerability in WP Media WP Rocket wp-rocket allows Code Injection.This issue affects WP Rocket: from n/a before 3.23.5.
Published: 2026-10-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The WP Rocket plugin for WordPress contains an executable regular expression error that can be triggered by crafted input. When exploited, the plugin may execute unintended code or throw an exception that exhausts resources, leading to a denial of service. The weakness is classified as CWE-624, indicating that untrusted data can lead to execution of malicious code. The vulnerability affects any version of WP Rocket installed before 3.23.5.

Affected Systems

WP Media’s WP Rocket WordPress plugin, versions earlier than 3.23.5. Any WordPress site that has an older instance of the plugin installed is potentially impacted.

Risk and Exploitability

With a CVSS score of 7.5, the vulnerability is considered high severity. No EPSS score is available, and it is not listed in the CISA KEV catalog, but the absence of a low exploitation probability metric does not diminish the risk of automated or attack‑targeted exploitation. The attack can occur remotely by sending requests that contain inputs triggering the faulty regular expression. Because the bug is fundamental to the plugin’s core regex handling, an attacker can repeatedly cause high CPU usage or code execution without authentication, making the risk substantial for all sites running the affected plugin.

Generated by OpenCVE AI on October 9, 2026 at 08:26 UTC.

Remediation

Vendor Solution

Update the WordPress WP Rocket plugin to the latest available version (at least 3.23.5).


OpenCVE Recommended Actions

  • Upgrade the WP Rocket plugin to version 3.23.5 or newer.
  • Review and remove any custom configurations that trigger large or complex regular expressions, particularly in caching or minification settings.
  • Implement monitoring for high CPU usage or repeated plugin errors and configure alerts for abnormal spikes.

Generated by OpenCVE AI on October 9, 2026 at 08:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description Executable Regular Expression Error vulnerability in WP Media WP Rocket wp-rocket allows Code Injection.This issue affects WP Rocket: from n/a before 3.23.5.
Title WordPress WP Rocket plugin < 3.23.5 - Denial of Service Attack vulnerability
Weaknesses CWE-624
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T07:00:48.876Z

Reserved: 2026-09-24T00:20:10.982Z

Link: CVE-2026-97076

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T07:17:19.350

Modified: 2026-10-09T13:20:48.273

Link: CVE-2026-97076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:00:03Z

Weaknesses
  • CWE-624

    Executable Regular Expression Error