PT-2024-18434 · WordPress · Wp Compress

Krzysztof Zając

·

Published

2024-04-09

·

Updated

2025-08-09

·

CVE-2024-1934

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions WP Compress – Image Optimizer plugin for WordPress versions up to, and including, 6.11.10
Description The issue allows unauthorized modification of data due to a missing capability check on the wps local compress:: construct function. This makes it possible for unauthenticated attackers to reset the CDN region and set a malicious URL to deliver images.
Recommendations For versions up to, and including, 6.11.10, update to a version higher than 6.11.10 to resolve the issue. As a temporary workaround, consider restricting access to the wps local compress:: construct function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1934

Affected Products

Wp Compress