WP Rocket has disclosed a security vulnerability that was fixed on August 27.
The issue could potentially have exposed:
-
WP Rocket account email address
-
WP Rocket license key
-
Cloudflare API key, if configured inside WP Rocket
-
Sucuri API key, if configured inside WP Rocket
WP Rocket says it currently has no reports of actual data exposure, but recommends taking precautionary action.
If you use WP Rocket, update to version 3.23.3.3 or newer as soon as possible.
If you configured Cloudflare or Sucuri through WP Rocket, it is also recommended to regenerate those API keys and replace them in WP Rocket.
Users with a Multi license may also want to contact WP Rocket support to rotate their license key, although WP Rocket considers the risk of license abuse to be low.
If you manage multiple WordPress sites, this is worth checking today.
Full text from WP Rocket:
We are writing to inform you of a security issue affecting WP Rocket, and to explain the steps we recommend you take.
What happened
WP Rocket had a security vulnerability that could have exposed your account email address, your WP Rocket license key, and, if you had configured them in WP Rocket, your Cloudflare API key and/or your Sucuri API key.
We were made aware of this issue during the night of August 26–27, and released a fix on August 27.
We have no reports of data being exposed at this time, but we strongly recommend updating to the latest version as soon as possible.
What you should do
Update WP Rocket to 3.23.3.3 now.
If you use Cloudflare and/or Sucuri integrations in WP Rocket, we recommend regenerating those API keys as a precaution. After generating a new key, make sure to update it in WP Rocket’s settings as well, so your integration keeps working correctly.
If you have a Multi license, there is a possibility someone could use your license key on additional sites up to your plan’s site limit before you’d notice. We consider this risk to be low, but if you’re concerned, you can contact our support team to have your license key rotated.
