T
Threats
WP Compress Cross-Site Request Forgery Vulnerability
Overview
CVE: CVE-2026-17608
Severity: Medium
CVSS: 6.5
Publication date: 16 August 2026
Last updated: 18 August 2026
A cross-site request forgery vulnerability affects the WP Compress – Instant Performance & Speed Optimization plugin for WordPress. The flaw is caused by missing or incorrect nonce validation in top-level template code.
An unauthenticated attacker could craft a request that deletes arbitrary WordPress options if a site administrator is tricked into taking an action such as clicking a malicious link. Targeted options may include siteurl, home, active_plugins, template and stylesheet, potentially causing a site outage or resetting active plugins and themes.
Affected Versions
WP Compress – Instant Performance & Speed Optimization
Affected: All versions up to and including 7.10.09
Fixed: 7.20.01
Not affected: 7.20.01 and later
Vulnerability Breakdown
CVE-2026-17608 – Cross-Site Request Forgery to Arbitrary Options Deletion
Severity: Medium
CVSS: 6.5
Description: Missing or incorrect nonce validation allows a forged request to trigger deletion of arbitrary WordPress options.
Impact: Deletion of critical configuration values may cause a site outage or reset active plugins and themes.
Conditions: The attacker does not need authentication, but must trick a site administrator into performing an action such as clicking a crafted link.
Weakness: CWE-352, Cross-Site Request Forgery
Mitigation
Update WP Compress to version 7.20.01 or later.
Confirm that no affected version remains active across production, staging or development WordPress sites.
After updating, review the site's URL, active plugin, theme and stylesheet settings for unexpected changes.
Summary for IT Teams
Products: WP Compress – Instant Performance & Speed Optimization for WordPress
Threat Level: Medium, CVSS 6.5
Action Required: Update WP Compress to version 7.20.01 or later and review critical WordPress options for unauthorised changes.
Reference
Need Help?
Secure ISS can help your organisation assess exposure, validate remediation and review WordPress security controls. Contact the Secure ISS team on 1300 769 460 or email us for assistance.

