CVE · High

CVE-2017-11658 — WP Rocket [wp-rocket] < 2.10.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-11658 WP Rocket [wp-rocket] < 2.10.4 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 2.10.4 2.10.4 2017-06-22

CVE-2017-11658

WP Rocket versions before 2.10.4 contain a local file inclusion vulnerability where the plugin's defense mechanism of removing directory traversal sequences can be circumvented. An attacker can bypass this incomplete filtering by injecting null bytes (0x00) into file paths, allowing them to read arbitrary files from the server through crafted requests containing encoded null bytes followed by traversal patterns.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.