vendor:
WP Rocket Plugin
by:
Paulos Yibelo
6.1
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: WP Rocket Plugin
Affected Version From: 36801
Affected Version To: 37896
Patch Exists: YES
Related CWE:
CPE: a:wp_rocket:wp_rocket
Platforms Tested: WordPress
2021
Local File Inclusion in WordPress WP Rocket Plugin
The Local File Inclusion vulnerability in WordPress WP Rocket Plugin allows an attacker to include local files from the target website, potentially exposing sensitive information like database credentials and enabling a complete database takeover. This issue was fixed in version 2.10.4.
Mitigation:
Ensure you update the WP Rocket Plugin to version 2.10.4 or higher to mitigate this vulnerability.