PT-2025-12790 · WordPress · Wp Compress

Michael Mazzolini

·

Published

2025-03-25

·

Updated

2025-08-11

·

CVE-2025-2109

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Compress – Instant Performance & Speed Optimization plugin for WordPress versions up to, and including, 6.30.15
Description The issue allows unauthenticated attackers to make web requests to arbitrary locations originating from the web application, which can be used to query information from internal services. This is achieved via the init() function.
Recommendations For versions up to, and including, 6.30.15, consider disabling the init() function as a temporary workaround until a patch is available. Restrict access to internal services to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-2109

Affected Products

Wp Compress