
PEACH
Un cadre d’isolation des locataires
CVE-2026-17608 is a Cross-Site Request Forgery (CSRF) vulnerability in the WP Compress – Instant Performance & Speed Optimization plugin for WordPress, developed by AresIT (also known as smartersite). The flaw affects all versions up to and including 7.10.09 and stems from missing or incorrect nonce validation in the plugin's top-level template code function. It was published on August 16, 2026, with a patch available as of the same date. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Wordfence).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), arising from the absence of proper nonce validation in the plugin's top-level template code, specifically in files such as classes/menu.class.php (lines 239 and 335), templates/admin/advanced_settings_v4.php (line 2378), and templates/admin/debug_tool.php (lines 550–551). Because WordPress nonces are not verified before processing state-changing requests, an attacker can craft a malicious HTML page or link that, when visited by an authenticated administrator, silently triggers deletion of arbitrary WordPress options. The attack vector is network-based, requires no privileges, but does require user interaction (social engineering the administrator into clicking a forged link) (GitHub Advisory, Wordfence).
Successful exploitation allows an unauthenticated attacker to delete critical WordPress options — including siteurl, home, active_plugins, template, and stylesheet — by tricking a logged-in administrator into triggering a forged request. This can result in complete site outage, forced deactivation of all plugins, or a full theme reset, effectively taking the WordPress site offline. While there is no direct confidentiality impact, the integrity impact is rated High due to the ability to corrupt core site configuration (GitHub Advisory, Wordfence).
As of the disclosure date (August 16, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering a site administrator, which raises the practical bar for attackers (GitHub Advisory, Wordfence).
readme.txt files.menu.class.php or debug_tool.php) without a valid nonce.siteurl, active_plugins, template), causing immediate site outage or plugin/theme reset (GitHub Advisory, Wordfence).wp-compress or wpc_ parameters) from unusual referrers or external domains.wp_options table, particularly for keys siteurl, home, active_plugins, template, or stylesheet.wp-content/debug.log) for errors related to missing options or plugin deactivation events coinciding with suspicious admin activity (GitHub Advisory).WordPress site administrators should update the WP Compress – Instant Performance & Speed Optimization plugin to a version newer than 7.10.09, as a patch was released on August 16, 2026 (changeset available in the WordPress plugin repository). Until an update is applied, administrators should exercise caution with unsolicited links and consider temporarily deactivating the plugin on sensitive sites. Additionally, implementing a Web Application Firewall (WAF) with CSRF protection rules and conducting security awareness training for administrators can reduce exposure (GitHub Advisory, Wordfence).
The vulnerability was reported and disclosed by Wordfence, which maintains a threat intelligence database for WordPress security issues. Coverage has been picked up by standard vulnerability aggregators including VulDB, Vulners, CIRCL, and ENISA's EUVD. No notable independent researcher commentary or significant social media discussion has been identified beyond automated CVE notification channels (Wordfence, GitHub Advisory).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."