{
 "id": "WPSEC-2026-0697",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0697/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0697/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0697/index.md",
 "title": "WP Compress <= 7.25.00 - Authenticated (Subscriber+) Privilege Escalation via Plugin Role Permissions",
 "description": "The WP Compress plugin for WordPress is vulnerable to Privilege Escalation via the User Permissions role matrix in all versions up to, and including, 7.25.00, due to an incorrect authorization check in wps_ic_users::permissionEnabled(). The function treated any stored '<role>_purge' or '<role>_manage_wpc' entry as a grant, whatever its value. When an administrator revoked a role's access, the settings handlers stored the entry as '0', so the role kept the manage_wpc_settings and manage_wpc_purge capabilities. This makes it possible for authenticated attackers whose role (for example subscriber or contributor) was once given plugin access and later had it revoked to keep accessing and changing the plugin's settings and purge functions.",
 "plugin": {
  "slug": "wp-compress-image-optimizer",
  "name": "WP Compress",
  "full_name": "WP Compress – Instant Performance & Speed Optimization",
  "wordpress_org": "https://wordpress.org/plugins/wp-compress-image-optimizer/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-compress-image-optimizer/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-compress-image-optimizer"
 },
 "type": "PRIV",
 "cwe": [
  "CWE-863"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.0,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "6.60.06",
    "from_inclusive": true,
    "to": "7.26.00",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 6.60.06 before 7.26.00"
  ]
 },
 "introduced_in": "6.60.06",
 "fixed_in": "7.26.00",
 "remediation": "Update to 7.26.00 or later.",
 "fix_released": "2026-10-08T12:49:10+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:11.475804+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0697/",
  "https://plugins.svn.wordpress.org/wp-compress-image-optimizer/tags/7.26.00/",
  "https://wordpress.org/plugins/wp-compress-image-optimizer/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-compress-image-optimizer",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}