PT-2026-20713 · WordPress · Aresit Wp Compress

Nguyen Ba Khanh

·

Published

2026-02-19

·

Updated

2026-02-19

·

CVE-2026-25370

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions AresIT WP Compress versions through 6.60.28
Description An issue exists in AresIT WP Compress wp-compress-image-optimizer related to incorrectly configured access control security levels, potentially allowing unauthorized access. The issue involves a missing authorization check.
Recommendations Update AresIT WP Compress to a version later than 6.60.28.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-25370

Affected Products

Aresit Wp Compress