CVE-2025-57899: WordPress WP Compress Plugin <= 6.50.54 - Broken Access Control Vulnerability
Missing Authorization vulnerability in AresIT WP Compress allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP Compress: from n/a through 6.50.54.
Other sources
Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Compress: from n/a through <= 6.50.54.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57899?
CVE-2025-57899 is considered a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-57899?
To fix CVE-2025-57899, update the AresIT WP Compress plugin to version 6.50.55 or later.
What impact does CVE-2025-57899 have on my website?
CVE-2025-57899 can allow attackers to access and utilize functions that should be restricted, compromising your website's security.
Which versions are affected by CVE-2025-57899?
CVE-2025-57899 affects AresIT WP Compress plugin versions from n/a up to and including 6.50.54.
Is authentication required to exploit CVE-2025-57899?
No, CVE-2025-57899 allows attackers to exploit vulnerable functionality without proper authentication.