CVE Database /
CVE-2017-11658
CVE · High
CVE-2017-11658 — WP Rocket [wp-rocket] < 2.10.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2017-11658
|
WP Rocket [wp-rocket] < 2.10.4 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
High
7.5
|
< 2.10.4
|
2.10.4 |
2017-06-22 |
—
|
CVE-2017-11658
WP Rocket versions before 2.10.4 contain a local file inclusion vulnerability where the plugin's defense mechanism of removing directory traversal sequences can be circumvented. An attacker can bypass this incomplete filtering by injecting null bytes (0x00) into file paths, allowing them to read arbitrary files from the server through crafted requests containing encoded null bytes followed by traversal patterns.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings