Reflected XSS Vulnerability in WP Compress Plugin for WordPress
CVE-2026-9066
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 23 July 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-9066?
The WP Compress plugin for WordPress prior to version 7.10.04 is susceptible to a Reflected XSS vulnerability due to improper validation of a query parameter that directs the asset CDN host. This security flaw allows attackers to manipulate script URLs, injecting malicious JavaScript that executes within the context of the victim's session. As a result, malicious actors can exploit this vulnerability to perform unauthorized actions on behalf of users, posing significant risks to website integrity and user security.
Affected Version(s)
WP Compress 0 < 7.10.04
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.