Impact
The WP Rocket plugin for WordPress contains an executable regular expression error that can be triggered by crafted input. When exploited, the plugin may execute unintended code or throw an exception that exhausts resources, leading to a denial of service. The weakness is classified as CWE-624, indicating that untrusted data can lead to execution of malicious code. The vulnerability affects any version of WP Rocket installed before 3.23.5.
Affected Systems
WP Media’s WP Rocket WordPress plugin, versions earlier than 3.23.5. Any WordPress site that has an older instance of the plugin installed is potentially impacted.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability is considered high severity. No EPSS score is available, and it is not listed in the CISA KEV catalog, but the absence of a low exploitation probability metric does not diminish the risk of automated or attack‑targeted exploitation. The attack can occur remotely by sending requests that contain inputs triggering the faulty regular expression. Because the bug is fundamental to the plugin’s core regex handling, an attacker can repeatedly cause high CPU usage or code execution without authentication, making the risk substantial for all sites running the affected plugin.
OpenCVE Enrichment