{"id":328933,"date":"2026-08-29T08:44:21","date_gmt":"2026-08-29T06:44:21","guid":{"rendered":"https:\/\/borncity.com\/blog\/?p=328933"},"modified":"2026-08-29T08:45:05","modified_gmt":"2026-08-29T06:45:05","slug":"wordpress-plugins-wprocket-givewp-und","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2026\/08\/29\/wordpress-plugins-wprocket-givewp-und\/","title":{"rendered":"WordPress-Plugins WPRocket, GiveWP und miniOrange"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2014\/07\/wp_thumb.jpg\" alt=\"\" width=\"64\" height=\"64\" align=\"left\" \/>Kurze Information: Derzeit sind wieder diverse Sicherheitsl\u00fccken in WordPress-Plugins (WPRocket, GiveWP und miniOrange) bekannt geworden. Nutzer dieser Plugins sollten diese unverz\u00fcglich aktualisieren, da sonst die \u00dcbernahme der WordPress-Instanz droht.<\/p>\n<p><!--more--><\/p>\n<h2>WordPress-Plugins WPRocket aktualisieren<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg02.met.vgwort.de\/na\/72763d93452d4ff19a4ec01f4580f104\" alt=\"\" width=\"1\" height=\"1\" \/>Blog-Leser Christof P. hat mich gestern per Mail \u00fcber ein Problem im WordPress-Plugins WPRocket informiert. Er schrieb mir, dass das Caching Plugin WPRocket eine gravierende Sicherheitsl\u00fccke habe. Der Anbieter hat den Leser zum 28. August 2026 informiert und schrieb:<\/p>\n<blockquote><p>Hi Christof\u200b\u200b,<br \/>\nWe are writing to inform you of a security issue affecting WP Rocket, and to explain the steps we recommend you take.<br \/>\n\u200b<br \/>\nWhat happened<br \/>\nWP Rocket had a security vulnerability that could have exposed your account email address, your WP Rocket license key, and, if you had configured them in WP Rocket, your Cloudflare API key and\/or your Sucuri API key.<br \/>\n\u200b<br \/>\nWe were made aware of this issue during the night of August 26\u201327, and released a fix on August 27.<br \/>\n\u200b<br \/>\nWe have no reports of data being exposed at this time, but we strongly recommend updating to the latest version as soon as possible.<br \/>\n\u200b<br \/>\nWhat you should do<\/p>\n<p>Update WP Rocket to 3.23.3.3 now.<br \/>\nIf you use Cloudflare and\/or Sucuri integrations in WP Rocket, we recommend regenerating those API keys as a precaution. After generating a new key, make sure to update it in WP Rocket's settings as well, so your integration keeps working correctly.<\/p>\n<p>If you have a Multi license, there is a possibility someone could use your license key on additional sites up to your plan's site limit before you'd notice. We consider this risk to be low, but if you're concerned, you can contact our support team to have your license key rotated.<br \/>\n\u200b<br \/>\nWe take the security of our users' data seriously, and we're truly sorry for the concern this may cause. If you have any questions, please don't hesitate to reply to this email.<\/p><\/blockquote>\n<p>Christof schrieb dazu: \"Besonders unsch\u00f6n ist die M\u00f6glichkeit zur Exfiltration sensibler Daten\". Ich selbst habe das Plugin nicht in Gebrauch, aber wer dieses nutzt, sollte dringend aktualisieren.<\/p>\n<h2>Weiter Plugins mit Schwachstellen<\/h2>\n<p>Die letzten Tage sind mit bei den Kollegen von Bleeping Computer ebenfalls Hinweise auf Schwachstellen in Plugins aufgefallen. Da ich keines dieser Plugins verwendet, hatte ich das nicht aufgegriffen. Hier die betreffenden Artikel, falls jemand Bedarf hat:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands\/\" target=\"_blank\" rel=\"noopener\">GiveWP WordPress donation plugin flaw lets hackers execute server commands<\/a><\/li>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks\/\" target=\"_blank\" rel=\"noopener\">Critical Elementor Pro bug exposes WordPress sites to RCE attacks<\/a><\/li>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks\/\" target=\"_blank\" rel=\"noopener\">Hackers target WordPress sites in miniOrange auth bypass attacks<\/a><\/li>\n<\/ul>\n<p>Wer diese Plugins und Erweiterungen nutzt, sollte also aktualisiert haben oder aktualisieren. Bisher hat mich mein Ansatz zum minimalen Einsatz von Plugins, zur Begrenzung des Zugangs \u00fcber Nutzerkonten sowie die \u00dcberwachung der Plugins auf Updates vor solchen Schwachstellen und vor allem deren Ausnutzung bisher bewahrt hat.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kurze Information: Derzeit sind wieder diverse Sicherheitsl\u00fccken in WordPress-Plugins (WPRocket, GiveWP und miniOrange) bekannt geworden. Nutzer dieser Plugins sollten diese unverz\u00fcglich aktualisieren, da sonst die \u00dcbernahme der WordPress-Instanz droht.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[426,7459,185,1574],"tags":[4328,3836,4315,4349],"class_list":["post-328933","post","type-post","status-publish","format-standard","hentry","category-sicherheit","category-software","category-update","category-wordpress","tag-sicherheit","tag-software","tag-update","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/328933","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=328933"}],"version-history":[{"count":3,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/328933\/revisions"}],"predecessor-version":[{"id":328937,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/328933\/revisions\/328937"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=328933"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=328933"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=328933"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}