Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket allows Stored XSS.This issue affects WP Rocket: from n/a through 3.19.4.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Mar 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wp Media Wp Media wp Rocket |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wp Media Wp Media wp Rocket |
Thu, 19 Mar 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket allows Stored XSS.This issue affects WP Rocket: from n/a through 3.19.4. | |
| Title | WordPress WP Rocket plugin <= 3.19.4 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published: 2026-03-19T05:21:26.027Z
Updated: 2026-03-19T05:21:26.027Z
Reserved: 2026-02-25T12:13:30.134Z
Link: CVE-2026-28044
No data.
Status : Received
Published: 2026-03-19T06:16:26.173
Modified: 2026-03-19T06:16:26.173
Link: CVE-2026-28044
No data.