📦 Wp Compress

by Wpcompress

🔍 What is Wp Compress?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-6699

CRITICAL CVSS 9.1 Jan 11, 2024

The WP Compress Image Optimizer WordPress plugin contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files on the server via the css parameter. This af...

CVE-2025-47546

HIGH CVSS 7.1 May 7, 2025

A Cross-Site Request Forgery (CSRF) vulnerability in the AresIT WP Compress WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions. This affects all...

CVE-2025-2110

HIGH CVSS 8.8 Mar 26, 2025

The WP Compress WordPress plugin has missing capability checks on AJAX functions, allowing authenticated users with Subscriber-level access or higher to access, modify, or delete sensitive plugin sett...

CVE-2024-47384

HIGH CVSS 7.1 Oct 5, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by the WP Compress plugin. When users visit a specially crafted URL, the script executes in their browser, pote...

CVE-2024-1934

HIGH CVSS 7.5 Apr 9, 2024

This vulnerability in the WP Compress – Image Optimizer WordPress plugin allows unauthenticated attackers to reset the CDN region and set malicious URLs for image delivery. It affects all versions u...

CVE-2025-47479

MEDIUM CVSS 5.3 Jul 4, 2025

A weak authentication vulnerability in AresIT WP Compress WordPress plugin allows attackers to bypass authentication mechanisms and gain unauthorized access. This affects all WordPress sites running W...

CVE-2023-6812

MEDIUM CVSS 4.3 May 14, 2024

The WP Compress Image Optimizer WordPress plugin contains an open redirect vulnerability that allows unauthenticated attackers to redirect users to malicious websites. This affects all WordPress sites...