SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17608

MEDIUM · CVSS 6.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-16 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The WP Compress plugin for WordPress is vulnerable to Cross-Site Request Forgery due to inadequate nonce validation, allowing unauthenticated attackers to execute unauthorized actions. This vulnerability can lead to the deletion of crucial WordPress options, potentially resulting in site outages or resets of plugins and themes. WordPress site administrators using this plugin should prioritize applying updates to mitigate the risk of exploitation.

CVE
CVE-2026-17608
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%
WordPress

Original NVD Description

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or incorrect nonce validation on the (top-level template code) function. This makes it possible for unauthenticated attackers to delete arbitrary WordPress options, including critical ones such as siteurl, home, active_plugins, template, and stylesheet, causing site outage or a full plugin and theme reset via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.