A critical vulnerability has been identified in the WP Compress plugin for WordPress, affecting versions prior to 7.20.01. This vulnerability enables unauthenticated attackers to execute arbitrary code remotely, posing a severe risk to affected systems. The flaw resides in the plugin's handling of certain requests, allowing exploitation without requiring authentication. WordPress sites using the WP Compress plugin with outdated versions are at significant risk of compromise. Attackers could leverage this vulnerability to gain full control over the affected server, leading to data breaches, service disruption, or further lateral movement within a network. The CVSS score of 10.0 reflects the high severity of this issue. Immediate action is recommended: update the WP Compress plugin to version 7.20.01 or later to mitigate the risk. Administrators should also review their WordPress installation for any other outdated plugins or themes that may introduce similar vulnerabilities. Failure to address this vulnerability could result in complete system compromise. Organizations relying on WordPress should prioritize patching to prevent exploitation by malicious actors.
CRITICAL
CVSS 10.0
CVE-2026-73343
2026-08-20
Critical RCE Vulnerability in WP Compress Plugin (CVE-2026-73343)
Unauthenticated Remote Code Execution (RCE) vulnerability in WP Compress plugin versions below 7.20.01 allows attackers to execute arbitrary code on affected WordPress installations.