Extension WordPress

Vulnérabilités WP Compress – Instant Performance & Speed Optimization

Cette page rassemble les failles publiées pour WP Compress – Instant Performance & Speed Optimization, leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
1Critiques
13Avec correctif
9,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WP Compress – Instant Performance & Speed Optimization

13 fiches

CVE-2025-47479 Élevée · 7,3
WP Compress – Instant Performance & Speed Optimization

WP Compress <= 6.30.30 – Unauthenticated Broken Authentication

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to broken authentication in all versions up to, and including, 6.30.30. This makes it possible for unauthenticated attackers to access functionality they should not…

Versions affectées

*-6.30.30

Correctif

6.30.31

Publication

03/07/2025

CVE-2025-2110 Élevée · 8,8
WP Compress – Instant Performance & Speed Optimization

WP Compress <= 6.30.15 – Authenticated (Subscriber+) Missing Authorization via Multiple Functions

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on its on its AJAX functions in all versions up to,…

Versions affectées

*-6.30.15

Correctif

6.30.16

Publication

25/03/2025

CVE-2025-2109 Moyenne · 5,8
WP Compress – Instant Performance & Speed Optimization

WP Compress <= 6.30.15 – Unauthenticated Server-Side Request Forgery via init Function

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.30.15 via the init() function. This makes it possible for unauthenticated attackers to…

Versions affectées

*-6.30.15

Correctif

6.30.16

Publication

24/03/2025

CVE-2024-12047 Moyenne · 6,1
WP Compress – Instant Performance & Speed Optimization

WP Compress – Instant Performance & Speed Optimization <= 6.30.03 – Reflected Cross-Site Scripting via custom_server Parameter

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘custom_server’ parameter in all versions up to, and including, 6.30.03 due to insufficient input sanitization and output escaping.…

Versions affectées

*-6.30.03

Correctif

6.30.04

Publication

03/01/2025

CVE-2024-47384 Moyenne · 6,1
WP Compress – Instant Performance & Speed Optimization

WP Compress – Image Optimizer [All-In-One] <= 6.20.13 – Reflected Cross-Site Scripting

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.20.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

*-6.20.13

Correctif

6.21.01

Publication

30/09/2024

CVE-2023-6812 Moyenne · 4,3
WP Compress – Instant Performance & Speed Optimization

WP Compress – Image Optimizer [All-In-One] <= 6.20.01 – Open Redirect via css

The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This is due to insufficient validation on the redirect url supplied via the 'css' parameter.…

Versions affectées

*-6.20.01

Correctif

6.20.02

Publication

13/05/2024

CVE-2024-4445 Moyenne · 6,5
WP Compress – Instant Performance & Speed Optimization

WP Compress – Image Optimizer [All-In-One] <= 6.20.01 – Missing Authorization

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible…

Versions affectées

*-6.20.01

Correctif

6.20.02

Publication

13/05/2024

CVE-2024-32106 Moyenne · 4,3
WP Compress – Instant Performance & Speed Optimization

WP Compress – Image Optimizer [All-In-One] <= 6.10.35 – Cross-Site Request Forgery

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.35. This is due to missing or incorrect nonce validation on several functions. This makes…

Versions affectées

*-6.10.35

Correctif

6.11.01

Publication

11/04/2024

CVE-2024-1934 Élevée · 7,5
WP Compress – Instant Performance & Speed Optimization

WP Compress – Image Optimizer <= 6.11.08 – Missing Authorization to Unauthenticated CDN Modification

The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' function in all versions up to, and including, 6.11.10. This makes it possible…

Versions affectées

*-6.11.10

Correctif

6.11.11

Publication

21/03/2024

CVE-2023-6699 Critique · 9,1
WP Compress – Instant Performance & Speed Optimization

WP Compress – Image Optimizer [All-In-One] <= 6.10.33 – Unauthenticated Directory Traversal via css

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated attackers to read the contents…

Versions affectées

*-6.10.33

Correctif

6.10.34

Publication

03/01/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités