Description
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Published: 2026-08-18
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthorized attackers can execute arbitrary code on affected WordPress sites without authentication. The flaw exists in all WP Compress versions below 7.20.01, allowing an attacker to craft a request that triggers malicious code execution, leading to full compromise of the web server and any data it hosts.

Affected Systems

Any website that has the AresIT WP Compress plugin installed at a version older than 7.20.01 is vulnerable. All WordPress installations that use this plugin are at risk until the plugin is updated or removed.

Risk and Exploitability

The vulnerability carries a CVSS score of 10, indicating catastrophic impact. An EPSS score is not available, so the exact likelihood of exploitation is unknown, but the high severity rating and lack of authentication requirement make it a high priority target. The vulnerability is not listed in the CISA KEV catalog, but the absolute nature of the flaw means it can be exploited by threat actors with minimal effort.

Generated by OpenCVE AI on August 18, 2026 at 16:23 UTC.

Remediation

Vendor Solution

Update the WordPress WP Compress Plugin to the latest available version (at least 7.20.01).


OpenCVE Recommended Actions

  • Upgrade the WP Compress Plugin to version 7.20.01 or newer.
  • If an upgrade cannot be applied immediately, disable or uninstall the plugin to block the attack surface.
  • Monitor web server logs for unexpected upload or request activity to detect potential exploitation attempts.
  • Follow WordPress security best practices, such as enforcing strict file upload restrictions and limiting file permissions to mitigate other potential vulnerabilities.

Generated by OpenCVE AI on August 18, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Aresit
Aresit wp Compress
Wordpress
Wordpress wordpress
Vendors & Products Aresit
Aresit wp Compress
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Title WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Aresit Wp Compress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T19:48:21.270Z

Reserved: 2026-08-12T10:51:08.683Z

Link: CVE-2026-73343

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T15:17:02.943

Modified: 2026-08-18T15:17:02.943

Link: CVE-2026-73343

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T16:30:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')