Description
Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
Published: 2026-09-03
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows remote unauthenticated users to modify the WP Compress plugin settings without proper authorization. This flaw can lead to unintended configuration changes, potentially disabling image compression, impacting site performance, or exposing sensitive information. The weakness is identified as Missing Authorization (CWE‑862) and carries a CVSS score of 8.2, indicating high severity.

Affected Systems

The affected software is the WordPress WP Compress plugin developed by AresIT, specifically versions up to 7.21.28. The plugin is used within WordPress installations, and attackers can target any instance running an affected version. The vendor recommends updating to at least version 7.22.0 to remediate the issue.

Risk and Exploitability

The flaw can be exploited by sending crafted requests to the plugin's settings interface from any external source, without needing to log in. No documented exploit evidence is currently available, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high CVSS score and lack of authentication requirements mean that attackers could use it to alter site behavior, potentially creating a foothold for further compromise or causing denial of service. The EPSS score is not available, so the likelihood estimate is uncertain, but the inherent design flaw makes it a prime candidate for exploitation.

Generated by OpenCVE AI on September 3, 2026 at 17:25 UTC.

Remediation

Vendor Solution

Update the WordPress WP Compress Plugin to the latest available version (at least 7.22.0).


OpenCVE Recommended Actions

  • Update the WP Compress plugin to version 7.22.0 or later.
  • If an immediate update is not possible, restrict access to the plugin settings pages by limiting IP addresses or using a web application firewall to block malicious traffic.
  • Audit the plugin's configuration for unexpected changes and monitor logs for unauthorized activity.

Generated by OpenCVE AI on September 3, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
Title WordPress WP Compress plugin <= 7.21.28 - Settings Change vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-03T17:35:28.197Z

Reserved: 2026-09-02T09:57:31.410Z

Link: CVE-2026-84757

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:26.660

Modified: 2026-09-03T17:25:25.113

Link: CVE-2026-84757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T17:30:07Z

Weaknesses