CVE-2025-47479: WordPress WP Compress plugin <= 6.30.30 - Broken Authentication Vulnerability
Published Jul 4, 2025
·Updated
Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abuse.This issue affects WP Compress: from n/a through <= 6.30.30.
Affected Software
3 affected components
AresIT WP Compress<=6.30.30
WordPress WP Compress<=6.30.30
Wpcompress Wp Compress Wordpress<6.30.31
Remediation
Information
Update the WordPress WP Compress plugin to the latest available version (at least 6.30.31).
Event History
Jul 4, 2025
CVE Published
via MITRE·11:18 AM
Data Sourced
via MITRE·11:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47479?
CVE-2025-47479 is categorized as a weak authentication vulnerability that can lead to authentication abuse.
2
How do I fix CVE-2025-47479?
To fix CVE-2025-47479, upgrade to a patched version of AresIT WP Compress that is higher than 6.30.30.
3
Which versions of AresIT WP Compress are affected by CVE-2025-47479?
CVE-2025-47479 affects all versions of AresIT WP Compress up to and including 6.30.30.
4
What is the impact of CVE-2025-47479 on my site?
CVE-2025-47479 can potentially allow unauthorized users to gain access to protected areas of your site due to weak authentication.
5
Is CVE-2025-47479 specific to any particular website?
CVE-2025-47479 specifically affects any WordPress site using the vulnerable versions of WP Compress, regardless of the site's content.