CVE-2026-17608: WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Deletion
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or incorrect nonce validation on the (top-level template code) function. This makes it possible for unauthenticated attackers to delete arbitrary WordPress options, including critical ones such as siteurl, home, activeplugins, template, and stylesheet, causing site outage or a full plugin and theme reset via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: WP Compress – Instant Performance & Speed Optimizationto a version that resolves this vulnerability.Fixed in 7.10.09 - Compensating control
Protect against CSRF by ensuring the WordPress admin endpoints used by the WP Compress plugin require a valid nonce (correct nonce validation on the top-level template code function) before performing any action that deletes WordPress options.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17608?
The severity of CVE-2026-17608 is classified as medium with a score of 6.5.
What type of vulnerability is CVE-2026-17608?
CVE-2026-17608 is a Cross-Site Request Forgery (CSRF) vulnerability.
How can CVE-2026-17608 affect my WordPress site?
CVE-2026-17608 can allow unauthorized users to delete arbitrary options in the WP Compress plugin.
How do I fix CVE-2026-17608?
To fix CVE-2026-17608, you should upgrade the WP Compress plugin to a version later than 7.10.09.
Which software is impacted by CVE-2026-17608?
CVE-2026-17608 affects the WP Compress – Instant Performance & Speed Optimization plugin for WordPress.