WP Rocket security alert, August 28, 2026: a customer notice shared with Webless warns that a vulnerability could have exposed account email addresses, WP Rocket license keys, and Cloudflare or Sucuri API keys configured in WP Rocket. The notice recommends updating to 3.23.3.3 and regenerating those integration keys as a precaution.
The important catch: updating the plugin and replacing a potentially exposed key are two different jobs. If you use those integrations, do not stop at the successful update message. Check which credentials the site used, replace the relevant keys, and verify that the connected services still work.
The email says WP Rocket had no reports of data exposure at the time it was sent. Receiving this notice does not mean your website was hacked. It does mean you have a concrete update and credential-check task to complete now.
What the WP Rocket security alert says
According to the customer notice, WP Rocket learned about the issue during the night of August 26-27 and released a fix on August 27. The vendor recommends version 3.23.3.3. For customers who configured Cloudflare or Sucuri in WP Rocket, it also recommends generating replacement API keys and saving them in the integration settings.
The notice identifies three types of information at risk:
- the account email address associated with WP Rocket;
- the WP Rocket license key;
- Cloudflare and/or Sucuri API keys, if configured in WP Rocket.
For Multi licenses, the email describes a low risk that someone could use the license on additional sites within the plan’s limit. Concerned customers can ask WP Rocket support to rotate that license key.
What we could verify publicly: the WP Rocket changelog lists 3.23.3.3 as an August 27 release. However, the entry we checked describes a cache-clearing fatal-error fix, not the security disclosure. The exposure details above come from the customer notice, not from that changelog entry.
The notice does not give a complete affected-version range, a CVE identifier, or technical exploitation conditions. We have not independently confirmed those details. Do not assume that every older installation leaked data, that this requires WordPress 7.1, or that the absence of visible symptoms rules out exposure.
What the WP Rocket security alert means for your site
Start with the setup you actually have. Using Cloudflare for DNS is not the same as storing a Cloudflare API key in WP Rocket. Similarly, installing a Sucuri plugin does not establish that you configured WP Rocket’s Sucuri integration.
| Your situation | Action now | What that does not prove |
|---|---|---|
| You use WP Rocket but neither integration | Install the vendor-recommended update. Review the account email and license guidance. | No configured integration does not exclude the email or license concern. |
| You configured a Cloudflare key in WP Rocket | Update WP Rocket, regenerate the relevant key, and update every legitimate connection that used it. | A successful plugin update does not revoke the old key. |
| You configured a Sucuri Firewall key in WP Rocket | Regenerate the relevant Firewall integration key and save the replacement in WP Rocket. | An unrelated Sucuri key change may not replace the credential used here. |
| An agency manages the keys, or the fields are hidden | Ask the responsible administrator to confirm current and historical integration use without sending the secret. | A blank or masked field is not proof that no key was configured. |
| You see redirects, unknown admins, spam, or unexplained account changes | Preserve evidence and arrange a security investigation alongside containment. | These signs need investigation; they do not establish this WP Rocket issue as the entry point. |
If your site already shows unauthorized changes, review Webless hacked WordPress site recovery. The service covers malware cleanup for the named WordPress site or WooCommerce store. The page explains the scope, current price, and separate work before you order.
WP Rocket security alert: install the official update
Open your WordPress dashboard or type WP Rocket’s official address into your browser. Use your existing licensed account and normal update route. Avoid third-party download archives, unsolicited replacement ZIP files, and messages asking you to send a license key or API key to get the fix.
Before the update, confirm you have a recoverable backup and working administrator or hosting access. Keep any settings export private: treat configuration exports as sensitive, not as material to paste into a support forum.
- Record the installed WP Rocket version and the update time.
- Install 3.23.3.3, the version named in the notice, or a later official release that includes the fix.
- Reopen the Plugins screen and verify the installed version. Do not rely only on an update notification disappearing.
- Check the homepage, an internal page, administrator access, and your important form or checkout path.
- Continue with the relevant credential changes below. The update is not a substitute for that step.
If WordPress does not show the update, follow WP Rocket’s official update instructions and licensed manual-update route. If the plugin is inactive because it breaks the site, do not reactivate a known-broken version merely to trigger an update. Have your host or maintenance provider apply the official package using a recovery-aware method.
For package checks and rollback planning, our safe WordPress plugin update guide explains the difference between an authentic download and a change that is safe for your particular site.
Cloudflare: rotate the right key and check its other uses
WP Rocket’s Cloudflare add-on documentation says its native add-on uses a Global API key, not a scoped API token. This matters: copying a scoped token into that field is not a supported replacement.
Cloudflare explains that a Global API key carries the user’s permissions across their accessible resources. It is not necessarily limited to the one website you were looking at. Cloudflare also permits only one Global API key per user. See its Global API key guidance for the current change procedure and limitations.
Our practical recommendation is to make a short dependency list before rotation. Identify the other sites, plugins, hosting connections, or approved scripts that use the same credential. Record their names and responsible people, not the key itself. Otherwise, replacing it for one site can silently break another site’s authenticated integration.
A controlled Cloudflare rotation sequence
- Confirm the affected WP Rocket installation has the official update.
- Sign in directly to the correct Cloudflare account and confirm which user owns the key.
- In the profile’s API Tokens area, find the Global API key and use Cloudflare’s documented Change action.
- Store the replacement securely and update the legitimate systems on your dependency list, including WP Rocket.
- Test an authenticated integration action, such as the intended cache purge, and verify the result for the correct site.
Do not leave a suspected exposed credential active for days while building a perfect inventory. If you see unauthorized activity, involve the account owner or provider immediately and prioritize containment.
If the WordPress installation itself may still be compromised, do not enter fresh secrets into it before containment and cleanup. Coordinate revocation through the provider, then reconnect from a trusted site. Otherwise, a new credential could be exposed again.
The key may come from server-side configuration rather than the visible WP Rocket field. Ask your developer to check that route if the new value does not take effect. Hiding a field is not the same as rotating its credential, and the notice does not establish that a hidden configuration was exempt.
Cloudflare recommends scoped tokens where supported. That is sensible for a planned integration review, but it is separate from today’s key replacement. Verify the specific connector’s supported authentication before changing how it connects.
Sucuri: replace the Firewall integration credential
The WP Rocket Sucuri add-on synchronizes cache clearing with Sucuri’s Website Firewall. Its documentation identifies the credential as the Firewall API Key (for plugin).
If you configured that integration, sign in directly to the relevant Sucuri Firewall account and locate the correct site’s API controls. Regenerate the credential through the account’s current supported process, or ask Sucuri support to guide you. We have not verified a current universal regeneration button, so do not follow guessed menu steps.
Then save the replacement where your WP Rocket integration obtains it. Check any other legitimate consumer of the old credential and verify that cache synchronization works. Do not turn off the firewall, change DNS, or remove protection just to clear an authentication warning.
If a different Sucuri product or plugin also has an API key, do not assume it is interchangeable. Confirm the credential’s purpose first.
What about the WP Rocket license and account email?
The WP Rocket security alert treats license misuse separately from the Cloudflare and Sucuri credentials. If you have a Multi license and are concerned about unauthorized use, contact WP Rocket through your normal account or official support route and ask about rotation. Webless cannot rotate a vendor-issued WP Rocket license for you.
Keep the account email concern in perspective. The notice names the email address; it does not say that an email password, WordPress password, or payment-card number was exposed. Those are different claims and need separate evidence.
Be cautious about follow-up messages that mention your plugin or license. A convincing product name is not proof that a sender is legitimate. Open the vendor account directly rather than supplying secrets through a link in an unexpected message.
When does this become a hacked-site recovery job?
A vulnerability notice is a reason to patch and review credentials. Malware cleanup becomes relevant when there are signs of unauthorized changes to the site. An account-level incident can also need work outside WordPress, even if the homepage still looks normal.
| Evidence you have | Next useful check | Appropriate help |
|---|---|---|
| Only the email, with no suspicious activity found | Verify the update, applicable key replacements, and working integrations. | Your administrator or maintenance provider; do not assume a malware cleanup is necessary. |
| Unauthorized redirects, injected content, or unknown WordPress administrators | Preserve URLs, timestamps and host findings; investigate the site’s files and database. | A WordPress malware-removal and recovery specialist. |
| Unexplained Cloudflare settings, DNS changes, or provider-account access | Preserve provider audit records and involve the account owner. | The provider and an appropriate account-security specialist, not only a WordPress cleanup. |
| A suspected disclosure of personal or customer data | Preserve evidence and establish what happened before making assurances. | Qualified incident-response and privacy advice; this is separate from restoring website files. |
| The site works, but cache integration fails after rotation | Check the credential type, configuration location, and which consumers still use the old key. | The responsible developer or maintenance provider. |
For visible malicious redirects, the WordPress redirecting to spam guide explains the recovery boundary. Do not erase logs or restore an old database as your first response. That can remove evidence and overwrite recent orders or leads without resolving the entry point.
For a support request, send the domain, symptoms, approximate times, installed versions, and what you have already changed. Do not send full API keys, passwords, customer records, or unredacted logs through a public comment or initial chat.
This is separate from the WordPress 7.1 white-screen incident
The August 20 compatibility incident caused a PHP fatal error on some configurations. WP Rocket released 3.23.2.2 for that problem. Our WP Rocket and WordPress 7.1 white-screen guide covers its diagnostic signature and recovery steps.
This WP Rocket security alert concerns a different issue with a different action: the vendor now recommends 3.23.3.3 and applicable credential rotation. Being on the earlier crash hotfix is not the same as completing today’s security response. Conversely, a white screen alone is still not proof of a hack.
Complete the WP Rocket security alert response
Keep one short incident note for your site or managed-site list. This helps the next administrator distinguish a completed response from a task someone merely discussed.
- WP Rocket version confirmed after the update, with date and time.
- Whether Cloudflare or Sucuri credentials were configured, including any unresolved historical use.
- Which relevant keys were replaced, who owns them, and when the replacement happened.
- Which dependent integrations were updated and tested.
- Any suspicious findings and the support case handling them.
- Any license-rotation request still pending with WP Rocket.
Leave actual secrets out of that note. A screenshot saying the plugin is current proves only the version check. A working homepage proves only that the page loads. Neither proves that old credentials are invalid or that all account activity was legitimate.
Get the right Webless help, without paying for the wrong job
If you have found malware, unauthorized redirects, spam content, or rogue administrators, see Webless hacked WordPress site recovery and cleanup pricing. We remove malicious changes from the named WordPress website or WooCommerce store and check the agreed key functions after cleanup.
Review the service boundaries before ordering. Broader hosting, email or provider-account compromise, suspected data exposure, and forensic investigations are separate work. If you only need help completing the update and key rotation, contact us first so we can discuss the appropriate scope instead of treating every security email as a malware-cleanup order.