AresIT WP Compress
cpe:2.3:a:wpcompress:wp_compress:*:*:*:*:wordpress:*:*
- <= 6.30.30
A weak authentication vulnerability allowing authentication abuse has been identified in the AresIT WP Compress plugin for WordPress, affecting versions through 6.30.30. This vulnerability can be exploited to perform actions that should only be available to users with higher privileges, potentially leading to unauthorized admin access on the website.
Exploitation of this vulnerability could allow a malicious actor to gain admin access to the affected WordPress site.
Users of the WP Compress plugin should update to version 6.30.31 or later. Patchstack users can enable auto-updates for vulnerable plugins.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.