WP Compress – Instant Performance & Speed Optimization < 7.20.01 - Unauthenticated Remote Code Execution
critical
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 7.20.01. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for unauthenticated attackers to execute arbitrary code on the...
- CVSS:
- 9.8
- Affected:
- up to 7.20.01
- Fixed in:
- 7.20.01
- Disclosed:
- Aug 18, 2026
CVE-2026-73343 on NVD →
WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Deletion
medium
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or incorrect nonce validation on the (top-level template code) function. This makes it possible for unauthenticated attackers...
- CVSS:
- 6.5
- Affected:
- up to 7.10.09
- Fixed in:
- 7.20.01
- Disclosed:
- Aug 15, 2026
CVE-2026-17608 on NVD →
Compress <= 7.10.3 - Reflected Cross-Site Scripting
medium
The Compress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 7.10.3
- Fixed in:
- 7.10.04
- Disclosed:
- Jul 2, 2026
CVE-2026-9066 on NVD →
WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] <= 6.60.28 (unfixed)
unknown
[en] Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress: from n/a through <= 6.60.28.
- Affected:
- up to 6.60.28
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25370 on NVD →
Compress <= 6.60.28 - Missing Authorization
medium
The Compress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.60.28. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 6.60.28
- Fixed in:
- 6.60.29
- Disclosed:
- Feb 17, 2026
CVE-2026-25370 on NVD →
WP Compress <= 6.50.54 - Missing Authorization
medium
The WP Compress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.50.54. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 6.50.54
- Fixed in:
- 6.50.55
- Disclosed:
- Sep 22, 2025
CVE-2025-57899 on NVD →
WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] < 6.30.31
unknown
[en] Weak Authentication vulnerability in AresIT WP Compress allows Authentication Abuse. This issue affects WP Compress: from n/a through 6.30.30.
- Affected:
- up to 6.30.31
- Fixed in:
- 6.30.31
- Disclosed:
- Jul 4, 2025
CVE-2025-47479 on NVD →
WP Compress <= 6.30.30 - Unauthenticated Broken Authentication
high
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to broken authentication in all versions up to, and including, 6.30.30. This makes it possible for unauthenticated attackers to access functionality they should not have access to.
- CVSS:
- 7.3
- Affected:
- up to 6.30.30
- Fixed in:
- 6.30.31
- Disclosed:
- Jul 3, 2025
CVE-2025-47479 on NVD →
WP Compress <= 6.30.30 - Cross-Site Request Forgery
medium
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.30.30. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized a...
- CVSS:
- 4.3
- Affected:
- up to 6.30.30
- Fixed in:
- 6.30.31
- Disclosed:
- May 7, 2025
CVE-2025-47546 on NVD →
WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] < 6.30.31
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress allows Cross Site Request Forgery. This issue affects WP Compress: from n/a through 6.30.30.
- Affected:
- up to 6.30.31
- Fixed in:
- 6.30.31
- Disclosed:
- May 7, 2025
CVE-2025-47546 on NVD →
WP Compress <= 6.30.15 - Authenticated (Subscriber+) Missing Authorization via Multiple Functions
high
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on its on its AJAX functions in all versions up to, and including, 6.30.15. This makes it possible for authenticated attackers, with Subsc...
- CVSS:
- 8.8
- Affected:
- up to 6.30.15
- Fixed in:
- 6.30.16
- Disclosed:
- Mar 25, 2025
CVE-2025-2110 on NVD →
WP Compress <= 6.30.15 - Unauthenticated Server-Side Request Forgery via init Function
medium
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.30.15 via the init() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web ap...
- CVSS:
- 5.8
- Affected:
- up to 6.30.15
- Fixed in:
- 6.30.16
- Disclosed:
- Mar 24, 2025
CVE-2025-2109 on NVD →
WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] < 6.30.04
unknown
[en] The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘custom_server’ parameter in all versions up to, and including, 6.30.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated atta...
- Affected:
- up to 6.30.04
- Fixed in:
- 6.30.04
- Disclosed:
- Jan 4, 2025
CVE-2024-12047 on NVD →
WP Compress – Instant Performance & Speed Optimization <= 6.30.03 - Reflected Cross-Site Scripting via custom_server Parameter
medium
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘custom_server’ parameter in all versions up to, and including, 6.30.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...
- CVSS:
- 6.1
- Affected:
- up to 6.30.03
- Fixed in:
- 6.30.04
- Disclosed:
- Jan 3, 2025
CVE-2024-12047 on NVD →
WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] < 6.21.01
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One] allows Reflected XSS.This issue affects WP Compress – Image Optimizer [All-In-One]: from n/a through 6.20.13.
- Affected:
- up to 6.21.01
- Fixed in:
- 6.21.01
- Disclosed:
- Oct 5, 2024
CVE-2024-47384 on NVD →
WP Compress – Image Optimizer [All-In-One] <= 6.20.13 - Reflected Cross-Site Scripting
medium
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.20.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 6.20.13
- Fixed in:
- 6.21.01
- Disclosed:
- Sep 30, 2024
CVE-2024-47384 on NVD →
WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] < 6.20.02
unknown
[en] The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This is due to insufficient validation on the redirect url supplied via the 'css' parameter. This makes it possible for unauthenticated attackers to redirect users to pot...
- Affected:
- up to 6.20.02
- Fixed in:
- 6.20.02
- Disclosed:
- May 14, 2024
CVE-2023-6812 on NVD →
WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] < 6.20.02
unknown
[en] The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible for authenticated attackers, with subscriber-level permissions and abov...
- Affected:
- up to 6.20.02
- Fixed in:
- 6.20.02
- Disclosed:
- May 14, 2024
CVE-2024-4445 on NVD →
WP Compress – Image Optimizer [All-In-One] <= 6.20.01 - Missing Authorization
medium
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to...
- CVSS:
- 6.5
- Affected:
- up to 6.20.01
- Fixed in:
- 6.20.02
- Disclosed:
- May 13, 2024
CVE-2024-4445 on NVD →
WP Compress – Image Optimizer [All-In-One] <= 6.20.01 - Open Redirect via css
medium
The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This is due to insufficient validation on the redirect url supplied via the 'css' parameter. This makes it possible for unauthenticated attackers to redirect users to potentia...
- CVSS:
- 4.3
- Affected:
- up to 6.20.01
- Fixed in:
- 6.20.02
- Disclosed:
- May 13, 2024
CVE-2023-6812 on NVD →
WP Compress – Image Optimizer [All-In-One] <= 6.10.35 - Cross-Site Request Forgery
medium
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.35. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to perform unauthorized actions v...
- CVSS:
- 4.3
- Affected:
- up to 6.10.35
- Fixed in:
- 6.11.01
- Disclosed:
- Apr 11, 2024
CVE-2024-32106 on NVD →
WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] < 6.11.01
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One].This issue affects WP Compress – Image Optimizer [All-In-One]: from n/a through 6.10.35.
- Affected:
- up to 6.11.01
- Fixed in:
- 6.11.01
- Disclosed:
- Apr 11, 2024
CVE-2024-32106 on NVD →
WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] < 6.11.11
unknown
[en] The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' function in all versions up to, and including, 6.11.10. This makes it possible for unauthenticated attackers to reset the CDN region a...
- Affected:
- up to 6.11.11
- Fixed in:
- 6.11.11
- Disclosed:
- Apr 9, 2024
CVE-2024-1934 on NVD →
WP Compress – Image Optimizer <= 6.11.08 - Missing Authorization to Unauthenticated CDN Modification
high
The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' function in all versions up to, and including, 6.11.10. This makes it possible for unauthenticated attackers to reset the CDN region and se...
- CVSS:
- 7.5
- Affected:
- up to 6.11.10
- Fixed in:
- 6.11.11
- Disclosed:
- Mar 21, 2024
CVE-2024-1934 on NVD →
WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] < 6.10.34
unknown
[en] The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive infor...
- Affected:
- up to 6.10.34
- Fixed in:
- 6.10.34
- Disclosed:
- Jan 11, 2024
CVE-2023-6699 on NVD →
WP Compress – Image Optimizer [All-In-One] <= 6.10.33 - Unauthenticated Directory Traversal via css
critical
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive informatio...
- CVSS:
- 9.1
- Affected:
- up to 6.10.33
- Fixed in:
- 6.10.34
- Disclosed:
- Jan 3, 2024
CVE-2023-6699 on NVD →
WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] < 6.30.16
unknown
- Affected:
- up to 6.30.16
- Fixed in:
- 6.30.16
CVE-2025-2109 on NVD →
WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] < 6.30.16
unknown
- Affected:
- up to 6.30.16
- Fixed in:
- 6.30.16
CVE-2025-2110 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database