Vulnerabilities / WP Compress / WPSEC-2026-0697

WP Compress <= 7.25.00 - Authenticated (Subscriber+) Privilege Escalation via Plugin Role Permissions

Medium 5.0 CWE-863Fixed in 7.26.00
ID
WPSEC-2026-0697
Plugin
WP Compress – Instant Performance & Speed Optimization (wp-compress-image-optimizer)
Affected
from 6.60.06 before 7.26.00
Remediation
Update to 7.26.00 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Weakness
CWE-863
Usage
Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
WP Compress on WPSec AttackSurface
Fix released
Published

Description

The WP Compress plugin for WordPress is vulnerable to Privilege Escalation via the User Permissions role matrix in all versions up to, and including, 7.25.00, due to an incorrect authorization check in wps_ic_users::permissionEnabled(). The function treated any stored '<role>_purge' or '<role>_manage_wpc' entry as a grant, whatever its value. When an administrator revoked a role's access, the settings handlers stored the entry as '0', so the role kept the manage_wpc_settings and manage_wpc_purge capabilities. This makes it possible for authenticated attackers whose role (for example subscriber or contributor) was once given plugin access and later had it revoked to keep accessing and changing the plugin's settings and purge functions.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0