CVE-2026-84757: WordPress WP Compress plugin <= 7.21.28 - Settings Change vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
Affected Software
1 affected component
WP Compress<=7.21.28
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Compress pluginto a version that resolves this vulnerability.Fixed in 7.22.0
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker does not need authentication or user interaction to exploit it. The vulnerability has low attack complexity.
2
Which installations are affected?
WP Compress versions 7.21.28 and earlier are affected. The provided information does not state whether any particular configuration changes exposure.
3
How can I determine whether my site is affected?
Check the installed WP Compress plugin version. Sites running version 7.21.28 or an earlier version are affected according to the available data.