# WP Compress <= 7.25.00 - Authenticated (Subscriber+) Privilege Escalation via Plugin Role Permissions

- **ID:** WPSEC-2026-0697
- **Plugin:** WP Compress – Instant Performance & Speed Optimization (`wp-compress-image-optimizer`), https://wordpress.org/plugins/wp-compress-image-optimizer/
- **Affected versions:** from 6.60.06 before 7.26.00
- **Fixed in:** 7.26.00 (Update to 7.26.00 or later.)
- **Severity:** Medium 5.0 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L)
- **Weakness:** CWE-863
- **Usage among sites WPSec scans:** plugin Medium, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-compress-image-optimizer
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0697/

## Description

The WP Compress plugin for WordPress is vulnerable to Privilege Escalation via the User Permissions role matrix in all versions up to, and including, 7.25.00, due to an incorrect authorization check in wps_ic_users::permissionEnabled(). The function treated any stored '<role>_purge' or '<role>_manage_wpc' entry as a grant, whatever its value. When an administrator revoked a role's access, the settings handlers stored the entry as '0', so the role kept the manage_wpc_settings and manage_wpc_purge capabilities. This makes it possible for authenticated attackers whose role (for example subscriber or contributor) was once given plugin access and later had it revoked to keep accessing and changing the plugin's settings and purge functions.

## References

- https://wpsec.com/vuln/WPSEC-2026-0697/
- https://plugins.svn.wordpress.org/wp-compress-image-optimizer/tags/7.26.00/
- https://wordpress.org/plugins/wp-compress-image-optimizer/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0697/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
