Impact
Missing authorization checks in the AresIT WP Compress plugin version 6.50.54 and earlier allow any authenticated user to invoke functions normally protected by ACLs, enabling unauthorized access to image‑optimization features that could be abused to modify site content or upload malicious files, thereby compromising confidentiality, integrity, and potentially availability; this flaw is a classic instance of CWE‑862.
Affected Systems
The plugin is AresIT’s WP Compress for WordPress, affected from the earliest release through 6.50.54, and must be updated if running these versions on any WordPress installation.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low exploitation probability; however, the flaw remains unlisted in CISA's KEV catalog, so there are no known large‑scale exploitation campaigns, and the likely attack vector is web‑based interaction with the plugin by an authenticated user who gains access through ordinary WordPress login credentials.
OpenCVE Enrichment
EUVD