PT-2026-73134 · WordPress · Wp Compress
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WP Compress – Instant Performance & Speed Optimization versions prior to 7.10.10
Description
This issue is a Cross-Site Request Forgery (CSRF), which occurs when a malicious actor tricks a user into performing an action they did not intend to do. The flaw exists due to missing or incorrect nonce validation—a security token used to ensure requests are legitimate—within the (top-level template code) function. Unauthenticated attackers can exploit this to delete arbitrary WordPress options, including
siteurl, home, active plugins, template, and stylesheet, potentially leading to a full plugin and theme reset or a complete site outage.Recommendations
Update to a version later than 7.10.09.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Compress