Impact
The vulnerability allows remote unauthenticated users to modify the WP Compress plugin settings without proper authorization. This flaw can lead to unintended configuration changes, potentially disabling image compression, impacting site performance, or exposing sensitive information. The weakness is identified as Missing Authorization (CWE‑862) and carries a CVSS score of 8.2, indicating high severity.
Affected Systems
The affected software is the WordPress WP Compress plugin developed by AresIT, specifically versions up to 7.21.28. The plugin is used within WordPress installations, and attackers can target any instance running an affected version. The vendor recommends updating to at least version 7.22.0 to remediate the issue.
Risk and Exploitability
The flaw can be exploited by sending crafted requests to the plugin's settings interface from any external source, without needing to log in. No documented exploit evidence is currently available, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high CVSS score and lack of authentication requirements mean that attackers could use it to alter site behavior, potentially creating a foothold for further compromise or causing denial of service. The EPSS score is not available, so the likelihood estimate is uncertain, but the inherent design flaw makes it a prime candidate for exploitation.
OpenCVE Enrichment