← WordPress Vulnerabilities
WordPress security by component

WP Compress

WP Compress is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published Feb 19, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: wp-compress-image-optimizer

CVE-2026-25370: WP Compress: A security weakness

WP Compress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedFeb 19, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 19, 2026 CVE-2026-25370
WP Compress: A security weakness
WP Compress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 22, 2025 CVE-2025-57899
WP Compress: A security weakness
WP Compress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Mar 26, 2025 CVE-2025-2110
WP Compress – Instant Performance & Speed Optimization: A security weakness
WP Compress – Instant Performance & Speed Optimization is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVDPending
Mar 25, 2025 CVE-2025-2109
WP Compress – Instant Performance & Speed Optimization: Server-side request forgery
WP Compress – Instant Performance & Speed Optimization is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE5.8
NVDPending
Jan 04, 2025 CVE-2024-12047
WP Compress – Instant Performance & Speed Optimization: Cross-site scripting
WP Compress – Instant Performance & Speed Optimization is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
May 14, 2024 CVE-2024-4445
WP Compress – Image Optimizer [All-In-One]: Cross-site scripting
WP Compress – Image Optimizer [All-In-One] is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD4.3
Apr 11, 2024 CVE-2024-32106
WP Compress – Image Optimizer [All-In-One]: Cross-site request forgery
WP Compress – Image Optimizer [All-In-One] is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Apr 09, 2024 CVE-2024-1934
WP Compress – Image Optimizer: A security weakness
WP Compress – Image Optimizer is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending