Cross-Site Request Forgery Vulnerability in WP Compress Plugin for WordPress
CVE-2026-17608
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2026-17608?
The WP Compress plugin for WordPress is exposed to a Cross-Site Request Forgery due to inadequate nonce validation in its top-level template code. This vulnerability allows unauthenticated attackers to craft malicious requests that can delete essential WordPress options. If an unsuspecting site administrator clicks a deceptive link, an attacker may leverage this vulnerability to trigger a site outage or reset critical settings, like site URL and active plugins, potentially leading to significant disruption.
Affected Version(s)
WP Compress β Instant Performance & Speed Optimization 0 <= 7.10.09