Impact
Unauthorized attackers can execute arbitrary code on affected WordPress sites without authentication. The flaw exists in all WP Compress versions below 7.20.01, allowing an attacker to craft a request that triggers malicious code execution, leading to full compromise of the web server and any data it hosts.
Affected Systems
Any website that has the AresIT WP Compress plugin installed at a version older than 7.20.01 is vulnerable. All WordPress installations that use this plugin are at risk until the plugin is updated or removed.
Risk and Exploitability
The vulnerability carries a CVSS score of 10, indicating catastrophic impact. An EPSS score is not available, so the exact likelihood of exploitation is unknown, but the high severity rating and lack of authentication requirement make it a high priority target. The vulnerability is not listed in the CISA KEV catalog, but the absolute nature of the flaw means it can be exploited by threat actors with minimal effort.
OpenCVE Enrichment