CVE-2017-11658: Wp-Rocket

High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.

In the WP Rocket plugin 2.9.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypassed by using 0x00 bytes, as demonstrated by a .%00.../.%00.../ attack.

Affected products

  • Wp-Rocket Wp-Rocket: version 1.3.0 only; version 1.3.1 only; version 1.3.2 only; version 1.3.3 only; version 1.3.4 only; version 1.3.5 only; …

Published 2017-07-26. Last modified 2026-06-17.