Sceawere

Vulnerability Detail

CVE-2026-73343UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Compress Unauthenticated RCE Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
3h ago
Vendor
AresIT
Product
WP Compress
Attack Type
CWE-94 Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-08-18T15:17:02.943Z",
  "pubdate": "2026-08-18T15:17:02.943Z",
  "executiveSummary": "An unauthenticated Remote Code Execution (RCE) vulnerability has been identified in the WP Compress plugin for WordPress, specifically affecting versions prior to 7.20.01.\nThis critical security flaw permits remote, unauthenticated threat actors to execute arbitrary system commands or code within the context of the underlying web server process.\nThe vulnerability exposes affected WordPress installations to complete system compromise, unauthorized data exfiltration, and potential lateral movement within the hosting environment.\nExploitation requires network access to the target WordPress instance and the presence of the vulnerable plugin without requiring valid user authentication or specific privilege levels.\nDue to the severity of remote code execution coupled with a lack of authentication requirements, the associated risk is critical, necessitating immediate remediation to prevent widespread exploitation.",
  "technicalDetails": "The vulnerability exists within the WP Compress plugin for WordPress, specifically impacting all versions preceding 7.20.01.\nThe root cause stems from improper input validation and unsafe handling of user-supplied data passed to the application backend, allowing an attacker to inject arbitrary commands or code.\nAuthentication requirements are entirely absent, meaning any remote attacker can interact directly with the vulnerable component over the network without possessing valid credentials or low-level privileges.\nNetwork exposure is direct, as the vulnerable endpoint is accessible via standard HTTP/HTTPS protocols exposed by the WordPress application.\nThe exploitation method involves crafting a malicious HTTP request containing a payload designed to bypass inadequate sanitization filters implemented in the vulnerable component.\nThe attack flow proceeds as follows: First, the unauthenticated attacker identifies the target endpoint exposed by WP Compress. Second, the attacker transmits a specially crafted payload targeting the insecure function or file within the plugin. Third, the lack of robust parameter validation causes the application to insecurely process the input. Finally, the payload executes within the application context, granting the attacker arbitrary command execution capabilities on the server.\nPayload behavior during post-exploitation typically includes the deployment of web shells, establishing persistent backdoor access, reading sensitive configuration files such as wp-config.php, and leveraging the compromised host for further network pivoting.\nThe vulnerable component fails to securely handle requests, leading directly to the breakdown of security boundaries between untrusted network input and server-side execution functions."
}
CVE-2026-73343: WP Compress Unauthenticated RCE Vulnerability (CRITICAL Severity, CVSS: 10.0) - Sceawere