Kurze Information: Derzeit sind wieder diverse Sicherheitslücken in WordPress-Plugins (WPRocket, GiveWP und miniOrange) bekannt geworden. Nutzer dieser Plugins sollten diese unverzüglich aktualisieren, da sonst die Übernahme der WordPress-Instanz droht.
WordPress-Plugins WPRocket aktualisieren
Blog-Leser Christof P. hat mich gestern per Mail über ein Problem im WordPress-Plugins WPRocket informiert. Er schrieb mir, dass das Caching Plugin WPRocket eine gravierende Sicherheitslücke habe. Der Anbieter hat den Leser zum 28. August 2026 informiert und schrieb:
Hi Christof,
We are writing to inform you of a security issue affecting WP Rocket, and to explain the steps we recommend you take.
What happened
WP Rocket had a security vulnerability that could have exposed your account email address, your WP Rocket license key, and, if you had configured them in WP Rocket, your Cloudflare API key and/or your Sucuri API key.
We were made aware of this issue during the night of August 26–27, and released a fix on August 27.
We have no reports of data being exposed at this time, but we strongly recommend updating to the latest version as soon as possible.
What you should doUpdate WP Rocket to 3.23.3.3 now.
If you use Cloudflare and/or Sucuri integrations in WP Rocket, we recommend regenerating those API keys as a precaution. After generating a new key, make sure to update it in WP Rocket's settings as well, so your integration keeps working correctly.If you have a Multi license, there is a possibility someone could use your license key on additional sites up to your plan's site limit before you'd notice. We consider this risk to be low, but if you're concerned, you can contact our support team to have your license key rotated.
We take the security of our users' data seriously, and we're truly sorry for the concern this may cause. If you have any questions, please don't hesitate to reply to this email.
Christof schrieb dazu: "Besonders unschön ist die Möglichkeit zur Exfiltration sensibler Daten". Ich selbst habe das Plugin nicht in Gebrauch, aber wer dieses nutzt, sollte dringend aktualisieren.
Weiter Plugins mit Schwachstellen
Die letzten Tage sind mit bei den Kollegen von Bleeping Computer ebenfalls Hinweise auf Schwachstellen in Plugins aufgefallen. Da ich keines dieser Plugins verwendet, hatte ich das nicht aufgegriffen. Hier die betreffenden Artikel, falls jemand Bedarf hat:
- GiveWP WordPress donation plugin flaw lets hackers execute server commands
- Critical Elementor Pro bug exposes WordPress sites to RCE attacks
- Hackers target WordPress sites in miniOrange auth bypass attacks
Wer diese Plugins und Erweiterungen nutzt, sollte also aktualisiert haben oder aktualisieren. Bisher hat mich mein Ansatz zum minimalen Einsatz von Plugins, zur Begrenzung des Zugangs über Nutzerkonten sowie die Überwachung der Plugins auf Updates vor solchen Schwachstellen und vor allem deren Ausnutzung bisher bewahrt hat.



MVP: 2013 – 2016





Das WP Rocket Changelog für Version 3.23.3.3 und die verlinkte Issue #6759 sagen derzeit zu einer möglichen Auswirkung auf Sicherheit gar nichts, mhm:
Quelle: https://wp-rocket.me/changelog/