CVE-2026-73343
10.0AresIT · WP Compress
An unauthenticated remote code execution vulnerability exists in the WP Compress WordPress plugin due to improper control of code generation, allowing attackers to execute arbitrary commands.
Executive summary
The WP Compress plugin for WordPress contains a critical unauthenticated remote code execution vulnerability that allows attackers to fully compromise the affected system.
Vulnerability
This vulnerability is a code injection flaw (CWE-94) residing within the WP Compress plugin. It allows an unauthenticated remote attacker to bypass security controls and execute arbitrary code on the underlying server.
Business impact
Successful exploitation of this vulnerability grants an attacker full control over the affected WordPress installation and the underlying server environment. Given the critical CVSS score of 10.0, this risk includes complete data exfiltration, unauthorized access to sensitive information, and total system disruption. The potential for reputational damage and the loss of data integrity necessitates an immediate response to prevent exploitation.
Remediation
Immediate Action: Update the WP Compress plugin to version 7.20.01 or later immediately.
Proactive Monitoring: Monitor server access logs for unusual HTTP requests or suspicious outbound traffic originating from the web server.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to detect and block common code injection attempts targeting WordPress plugins.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this flaw is absolute, as it permits unauthenticated remote code execution. Security teams must prioritize patching this plugin immediately. If an immediate update is not feasible, administrators should consider deactivating the plugin until it can be updated to a secure version to prevent potential compromise.