Executable Regular Expression Error vulnerability in WP Media WP Rocket wp-rocket allows Code Injection.This issue affects WP Rocket: from n/a before 3.23.5.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-97076 exposes a critical code injection vulnerability in WP Rocket, one of WordPress's most popular performance optimization plugins. The flaw stems from improper handling of executable regular expressions (CWE-624), allowing attackers to inject and execute arbitrary code through maliciously crafted input. This vulnerability affects WP Rocket versions prior to 3.23.5 and poses significant risk to WordPress sites using the plugin—potentially affecting hundreds of thousands of installations. Any unauthenticated or authenticated attacker capable of triggering the vulnerable regex processing could achieve remote code execution, leading to complete site compromise, data theft, and malware distribution.
While this CVE lacks direct MITRE ATT&CK mapping, Casky's 754 security skills—powered by Claude AI's extended reasoning capabilities—would detect the attack patterns associated with code injection and execution. Practitioners using Casky would observe findings related to T1059 (Command and Scripting Interpreter) and T1190 (Exploit Public-Facing Application) as the underlying attack vectors. The platform's skill-based detection would flag suspicious regex evaluation patterns, unusual code execution flows originating from plugin directories, and anomalous parameter handling in WP Rocket's processing functions. Security teams would see behavioral indicators such as unexpected PHP execution, regex injection attempts in plugin configuration parameters, and post-exploitation command execution patterns—enabling rapid identification and response before attackers establish persistence or exfiltrate sensitive data.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-97076. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation