CVE-2017-11658: Wp-Rocket
High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.
In the WP Rocket plugin 2.9.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypassed by using 0x00 bytes, as demonstrated by a .%00.../.%00.../ attack.
Affected products
- Wp-Rocket Wp-Rocket: version 1.3.0 only; version 1.3.1 only; version 1.3.2 only; version 1.3.3 only; version 1.3.4 only; version 1.3.5 only; …
Published 2017-07-26. Last modified 2026-06-17.