CVE-2026-73343: WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Affected Software
1 affected component
WordPress WP Compress Plugin<7.20.01
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Compress pluginto a version that resolves this vulnerability.Fixed in 7.20.01
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Sites using WP Compress versions earlier than 7.20.01 are affected. The issue is reachable over the network and requires no authentication or user interaction.
2
What does an attacker need to exploit this vulnerability?
An attacker does not need an account or any privileges to exploit the issue. The supplied vector indicates low attack complexity and potential impact to confidentiality, integrity, and availability.
3
What should administrators do?
Upgrade WP Compress to version 7.20.01 or later. No alternative mitigation is provided in the available data.