Description
Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress: from n/a through <= 6.60.28.
Published: 2026-02-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Broken Access Control
Action: Patch
AI Analysis

Impact

AresIT WP Compress plugin for WordPress contains a missing authorization control that permits unauthorized users to access privileged functionality within the plugin. The flaw is a classic example of CWE‑862: Missing Authorization. The impact is that an attacker could view or modify image‑compression settings and other protected plugin resources, potentially enabling further privilege escalation on the site. Although the description does not detail all consequences, it is clear that confidentiality and integrity of plugin configuration may be compromised.

Affected Systems

The vulnerability affects the WP Compress image optimizer plugin from its earliest release through version 6.60.28. Any WordPress installation hosting one of these versions is at risk. The vendor is AresIT and the product is WP Compress.

Risk and Exploitability

CVSS v3 base score of 5.3 indicates moderate severity. The EPSS score of less than 1% shows the likelihood of exploitation is very low at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web‑based, inferred from the nature of the plugin and the absence of an authentication requirement in the description. An attacker can exploit the flaw by interacting with the plugin’s administration interface or by crafting requests that bypass the missing permission checks. Based on the description, it is inferred that the exploitation does not require prior authentication, allowing an unauthenticated user to gain unauthorized access to privileged plugin functionality.

Generated by OpenCVE AI on April 16, 2026 at 06:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WP Compress to a version newer than 6.60.28.
  • If an update is not available, restrict access to the plugin’s administrative area to trusted administrators only or disable the plugin until a patch is released.
  • Monitor the site for abnormal image‑compression activity and review access logs for suspicious requests.

Generated by OpenCVE AI on April 16, 2026 at 06:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Thu, 26 Feb 2026 19:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Fri, 20 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Aresit
Aresit wp Compress
Wordpress
Wordpress wordpress
Vendors & Products Aresit
Aresit wp Compress
Wordpress
Wordpress wordpress

Thu, 19 Feb 2026 08:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress: from n/a through <= 6.60.28.
Title WordPress WP Compress plugin <= 6.60.28 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Aresit Wp Compress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-24T18:07:15.809Z

Reserved: 2026-02-02T12:52:55.300Z

Link: CVE-2026-25370

cve-icon Vulnrichment

Updated: 2026-02-26T18:46:52.476Z

cve-icon NVD

Status : Deferred

Published: 2026-02-19T09:16:19.707

Modified: 2026-04-23T15:37:06.423

Link: CVE-2026-25370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T06:45:16Z

Weaknesses