WP Vulnerability WatchVulnerability data as of September 9, 2026

Vulnerability alerts / September 8, 2026

Vulnerability in WP Compress – Instant Performance & Speed Optimization — WF-42d4ec8b-d3ed-4aa3-a8b9-cddaf64a7531

MediumSeverity
CVSS 5.3
Estimated exploit probability
EPSS
10,000+ sitesInstalls
7.22.38Fixed in

What to do now

Update WP Compress – Instant Performance & Speed Optimization to 7.22.38 or later.

Affected versions

  • Everything up to and including 7.22.01

Affected: WP Compress – Instant Performance & Speed Optimization (plugin, wp-compress-image-optimizer)

Check: The plugin on wordpress.org / Our record for WP Compress – Instant Performance & Speed Optimization

What the vulnerability is

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.22.01. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to link the victim site to an attacker-controlled WP Compress account, overwrite plugin settings to an aggressive live-CDN preset, and gain the shared api_key that authenticates all nopriv HMAC-gated endpoints — enabling full control over cache purging, file deletion, opcode cache invalidation, and other privileged plugin operations. This vulnerability only affects fresh installations or lite/free-mode installs where no api_key is already stored, as the sole guard fails open when the stored key is absent.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/42d4ec8b-d3ed-4aa3-a8b9-cddaf64a7531
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts