WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in WP Compress – Instant Performance & Speed Optimization

Everything you need for a faster website – smart optimization, advanced caching, adaptive images, WebP creation, script improvements, optional CDN del …

15Reported vulnerabilities
9.8Highest CVSS score
7.21.28Latest version
10,000+Active installs

What to do now

Update WP Compress – Instant Performance & Speed Optimization to 7.20.01 or later. 15 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 15, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-73343 Critical 9.8 0.8% Before 7.20.01 7.20.01 August 18, 2026
CVE-2025-2110 High 8.8 0.4% Before 6.30.16 6.30.16 March 26, 2025
CVE-2024-1934 High 7.5 0.7% Before 6.11.11 6.11.11 April 9, 2024
CVE-2025-47479 High 7.3 0.3% 6.30.30 and earlier 6.30.31 July 3, 2025
CVE-2026-17608 Medium 6.5 0.2% 0 to 7.10.09 (inclusive) 7.20.01 August 16, 2026
CVE-2026-9066 Medium 6.1 0.3% 7.10.3 and earlier 7.10.04 July 2, 2026
CVE-2024-12047 Medium 6.1 0.4% Before 6.30.04 6.30.04 January 4, 2025
CVE-2024-47384 Medium 6.1 0.3% 6.20.13 and earlier 6.21.01 September 30, 2024
CVE-2023-6812 Medium 6.1 0.4% Before 6.20.02 6.20.02 May 14, 2024
CVE-2025-2109 Medium 5.8 0.4% Before 6.30.16 6.30.16 March 25, 2025
CVE-2026-25370 Medium 5.3 0.2% 6.60.28 and earlier 6.60.29 February 17, 2026
CVE-2025-57899 Medium 5.3 0.5% 6.50.54 and earlier 6.50.55 September 22, 2025
CVE-2025-47546 Medium 4.3 0.2% 6.30.30 and earlier 6.30.31 May 7, 2025
CVE-2024-4445 Medium 4.3 0.3% Before 6.20.02 6.20.02 May 14, 2024
CVE-2024-32106 Medium 4.3 0.2% 6.10.35 and earlier 6.11.01 April 11, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.