Junglewise Threat Intelligence

CVE-2026-84757: WP Compress unauthenticated settings change

CVE-2026-84757 · Severity: high · CVSS 8.2 · Published 2026-09-03

Executive brief

WP Compress is a WordPress plugin used to optimize and compress images on websites. An unauthenticated attacker can change critical site settings such as disabling security features or altering configurations, potentially locking legitimate administrators out of their own site or compromising site security without any credentials or authentication required.

Technical details

The vulnerability is a broken access control flaw (OWASP A1) in WP Compress versions up to 7.21.28 that allows unauthenticated settings modification. An attacker can directly change plugin or site configuration settings without providing valid WordPress authentication credentials. The attack requires only network access to the affected WordPress site with the vulnerable plugin installed. A successful exploit allows an attacker to disable security mechanisms, alter site behavior, or lock out administrators. The vulnerability was patched in version 7.22.0.

Affected products

  • WP Compress WP Compress <= 7.21.28

Timeline

  • 2026-09-03: disclosed
  • 2026-09-02: patched: Version 7.22.0 released

References

Related threats