ZeroHour

CVE-2026-84757

moderate

Unauthenticated Settings Change in WP Compress WordPress Plugin

CVSS 3.1
8.2 high
EPSS
<1%p13
Published
()
Modified
AI analysis

CVE-2026-84757 is a missing authorization flaw (CWE-862) in the WP Compress image optimization plugin for WordPress that lets an attacker change the plugin's settings without authenticating. Because the vulnerable endpoint requires no privileges and no user interaction, any site running version 7.21.28 or earlier is remotely triggerable by a simple unauthenticated network request. An attacker who succeeds can tamper with the plugin's configuration (integrity impact) and, per the CVSS scoring, can also cause limited disruption to the site's availability, for example by altering optimization behavior; no confidential data is exposed by this flaw itself. Any WordPress site running WP Compress 7.21.28 or earlier is affected, while other plugins and other products are not impacted. There is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS currently puts 30-day exploitation probability at only about 0.2%, so exploitation is believed to be absent or minimal so far.

What to do: Update WP Compress to the newest release beyond 7.21.28 as soon as one is available. If you cannot update immediately, restrict and monitor unauthenticated access to the plugin's AJAX/REST settings endpoints (e.g., via WAF rules) and audit the plugin's current settings for unexpected changes. Check your installed version and, if the plugin was left enabled but unused, consider deactivating it until patched.

Affected
WP Compress (WordPress image optimization plugin)<= 7.21.28
Estimated exposure
moderatetens of thousands of WordPress sites (roughly 10k-30k) — WP Compress is a long-listed plugin on the WordPress.org directory with an active install count on the order of ten thousand-plus, so exposure is limited to a modest fraction of the WordPress ecosystem rather than mass scale.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.