CVE-2026-84757
moderateUnauthenticated Settings Change in WP Compress WordPress Plugin
CVE-2026-84757 is a missing authorization flaw (CWE-862) in the WP Compress image optimization plugin for WordPress that lets an attacker change the plugin's settings without authenticating. Because the vulnerable endpoint requires no privileges and no user interaction, any site running version 7.21.28 or earlier is remotely triggerable by a simple unauthenticated network request. An attacker who succeeds can tamper with the plugin's configuration (integrity impact) and, per the CVSS scoring, can also cause limited disruption to the site's availability, for example by altering optimization behavior; no confidential data is exposed by this flaw itself. Any WordPress site running WP Compress 7.21.28 or earlier is affected, while other plugins and other products are not impacted. There is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS currently puts 30-day exploitation probability at only about 0.2%, so exploitation is believed to be absent or minimal so far.
What to do: Update WP Compress to the newest release beyond 7.21.28 as soon as one is available. If you cannot update immediately, restrict and monitor unauthenticated access to the plugin's AJAX/REST settings endpoints (e.g., via WAF rules) and audit the plugin's current settings for unexpected changes. Check your installed version and, if the plugin was left enabled but unused, consider deactivating it until patched.
| WP Compress (WordPress image optimization plugin) | <= 7.21.28 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.