PT-2026-26591 · WordPress · Rockpress

Phong Nguyen

·

Publicado

2026-03-20

·

Atualizado

2026-03-22

·

CVE-2026-3550

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions RockPress versions up to and including 1.0.17
Description The RockPress plugin for WordPress is susceptible to a missing authorization issue. This is due to the absence of capability checks on several AJAX actions – rockpress import, rockpress import status, rockpress last import, rockpress reset import, and rockpress check services. The plugin’s nonce is exposed to all authenticated users through an unconditionally enqueued admin script. Specifically, the ‘rockpress-admin’ script is enqueued on all admin pages, including profile.php, without any restrictions. The nonce for the ‘rockpress-nonce’ action is passed to this script via wp localize script. Because the AJAX handlers only verify the nonce and do not verify current user can(), any authenticated user, even those with Subscriber-level access, can extract the nonce from the HTML source code of any admin page. This allows them to trigger imports, reset import data, check service connectivity, and read import status information, actions that should be restricted to administrators.
Recommendations Update RockPress to a version later than 1.0.17.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3550

Produtos afetados

Rockpress