Extension WordPress
Vulnérabilités WP Compress – Instant Performance & Speed Optimization
Cette page rassemble les failles publiées pour WP Compress – Instant Performance & Speed Optimization, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Compress – Instant Performance & Speed Optimization
13 fiches
Compress <= 6.60.28 – Missing Authorization
The Compress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.60.28. This makes it possible for unauthenticated attackers to perform an unauthorized action.
*-6.60.28
6.60.29
17/02/2026
WP Compress <= 6.50.54 – Missing Authorization
The WP Compress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.50.54. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-6.50.54
6.50.55
22/09/2025
WP Compress <= 6.30.30 – Unauthenticated Broken Authentication
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to broken authentication in all versions up to, and including, 6.30.30. This makes it possible for unauthenticated attackers to access functionality they should not…
*-6.30.30
6.30.31
03/07/2025
WP Compress <= 6.30.30 – Cross-Site Request Forgery
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.30.30. This is due to missing or incorrect nonce validation on a function.…
*-6.30.30
6.30.31
07/05/2025
WP Compress <= 6.30.15 – Authenticated (Subscriber+) Missing Authorization via Multiple Functions
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on its on its AJAX functions in all versions up to,…
*-6.30.15
6.30.16
25/03/2025
WP Compress <= 6.30.15 – Unauthenticated Server-Side Request Forgery via init Function
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.30.15 via the init() function. This makes it possible for unauthenticated attackers to…
*-6.30.15
6.30.16
24/03/2025
WP Compress – Instant Performance & Speed Optimization <= 6.30.03 – Reflected Cross-Site Scripting via custom_server Parameter
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘custom_server’ parameter in all versions up to, and including, 6.30.03 due to insufficient input sanitization and output escaping.…
*-6.30.03
6.30.04
03/01/2025
WP Compress – Image Optimizer [All-In-One] <= 6.20.13 – Reflected Cross-Site Scripting
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.20.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-6.20.13
6.21.01
30/09/2024
WP Compress – Image Optimizer [All-In-One] <= 6.20.01 – Open Redirect via css
The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This is due to insufficient validation on the redirect url supplied via the 'css' parameter.…
*-6.20.01
6.20.02
13/05/2024
WP Compress – Image Optimizer [All-In-One] <= 6.20.01 – Missing Authorization
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible…
*-6.20.01
6.20.02
13/05/2024
WP Compress – Image Optimizer [All-In-One] <= 6.10.35 – Cross-Site Request Forgery
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.35. This is due to missing or incorrect nonce validation on several functions. This makes…
*-6.10.35
6.11.01
11/04/2024
WP Compress – Image Optimizer <= 6.11.08 – Missing Authorization to Unauthenticated CDN Modification
The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' function in all versions up to, and including, 6.11.10. This makes it possible…
*-6.11.10
6.11.11
21/03/2024
WP Compress – Image Optimizer [All-In-One] <= 6.10.33 – Unauthenticated Directory Traversal via css
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated attackers to read the contents…
*-6.10.33
6.10.34
03/01/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.