T

Threats

WP Compress Cross-Site Request Forgery Vulnerability

Overview

  • CVE: CVE-2026-17608

  • Severity: Medium

  • CVSS: 6.5

  • Publication date: 16 August 2026

  • Last updated: 18 August 2026

A cross-site request forgery vulnerability affects the WP Compress – Instant Performance & Speed Optimization plugin for WordPress. The flaw is caused by missing or incorrect nonce validation in top-level template code.

An unauthenticated attacker could craft a request that deletes arbitrary WordPress options if a site administrator is tricked into taking an action such as clicking a malicious link. Targeted options may include siteurl, home, active_plugins, template and stylesheet, potentially causing a site outage or resetting active plugins and themes.


Affected Versions

WP Compress – Instant Performance & Speed Optimization


Vulnerability Breakdown

CVE-2026-17608 – Cross-Site Request Forgery to Arbitrary Options Deletion

  • Severity: Medium

  • CVSS: 6.5

  • Description: Missing or incorrect nonce validation allows a forged request to trigger deletion of arbitrary WordPress options.

  • Impact: Deletion of critical configuration values may cause a site outage or reset active plugins and themes.

  • Conditions: The attacker does not need authentication, but must trick a site administrator into performing an action such as clicking a crafted link.

  • Weakness: CWE-352, Cross-Site Request Forgery


Mitigation

  • Update WP Compress to version 7.20.01 or later.

  • Confirm that no affected version remains active across production, staging or development WordPress sites.

  • After updating, review the site's URL, active plugin, theme and stylesheet settings for unexpected changes.


Summary for IT Teams

  • Products: WP Compress – Instant Performance & Speed Optimization for WordPress

  • Threat Level: Medium, CVSS 6.5

  • Action Required: Update WP Compress to version 7.20.01 or later and review critical WordPress options for unauthorised changes.


Reference


Need Help?

Secure ISS can help your organisation assess exposure, validate remediation and review WordPress security controls. Contact the Secure ISS team on 1300 769 460 or email us for assistance.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.