Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-17608 2 Aresit, Wordpress 2 Wp Compress – Instant Performance & Speed Optimization, Wordpress 2026-08-17 6.5 Medium
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or incorrect nonce validation on the (top-level template code) function. This makes it possible for unauthenticated attackers to delete arbitrary WordPress options, including critical ones such as siteurl, home, active_plugins, template, and stylesheet, causing site outage or a full plugin and theme reset via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2026-25370 2 Aresit, Wordpress 2 Wp Compress, Wordpress 2026-04-24 5.3 Medium
Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress: from n/a through <= 6.60.28.