plugin

Wp Compress Mainwp Vulnerabilities

3 known security issues reported for the Wp Compress Mainwp WordPress plugin. Most recent disclosed Nov 29, 2025.

3 medium

Running Wp Compress Mainwp on your site? Check whether your installed version is affected.

Scan your site free

Compress for MainWP <= 6.50.07 - Missing Authorization

medium

The Compress for MainWP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.50.07. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 6.50.07
Fix:
No patched version reported
Disclosed:
Nov 29, 2025

CVE-2025-64639 on NVD →

WP Compress for MainWP <= 6.30.32 - Missing Authorization

medium

The WP Compress for MainWP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.30.32. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 6.30.32
Fixed in:
6.50.05
Disclosed:
Jun 5, 2025

CVE-2025-30932 on NVD →

WP Compress for MainWP <= 6.30.03 - Authenticated (Subscriber+) Server-Side Request Forgery

medium

The WP Compress for MainWP plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.30.03. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which c...

CVSS:
6.4
Affected:
up to 6.30.03
Fixed in:
6.30.06
Disclosed:
Mar 28, 2025

CVE-2025-31076 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database