CVE-2024-12047: WP Compress – Instant Performance & Speed Optimization <= 6.30.03 - Reflected Cross-Site Scripting via custom_server Parameter
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘customserver’ parameter in all versions up to, and including, 6.30.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12047?
CVE-2024-12047 is classified as a high severity vulnerability due to its ability to exploit reflected cross-site scripting.
How do I fix CVE-2024-12047?
To fix CVE-2024-12047, upgrade the WP Compress plugin to the latest version beyond 6.30.03.
What versions of WP Compress are affected by CVE-2024-12047?
All versions of the WP Compress plugin up to and including 6.30.03 are affected by CVE-2024-12047.
What kind of vulnerability is CVE-2024-12047?
CVE-2024-12047 is a reflected cross-site scripting vulnerability.
Is there a patch available for CVE-2024-12047?
Yes, upgrading to the latest version of WP Compress will apply the necessary patch for CVE-2024-12047.