
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-17608 is a Cross-Site Request Forgery (CSRF) vulnerability in the WP Compress – Instant Performance & Speed Optimization plugin for WordPress, developed by AresIT (also known as smartersite). The flaw affects all versions up to and including 7.10.09 and stems from missing or incorrect nonce validation in the plugin's top-level template code function. It was published on August 16, 2026, with a patch available as of the same date. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Wordfence).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), arising from the absence of proper nonce validation in the plugin's top-level template code, specifically in files such as classes/menu.class.php (lines 239 and 335), templates/admin/advanced_settings_v4.php (line 2378), and templates/admin/debug_tool.php (lines 550–551). Because WordPress nonces are not verified before processing state-changing requests, an attacker can craft a malicious HTML page or link that, when visited by an authenticated administrator, silently triggers deletion of arbitrary WordPress options. The attack vector is network-based, requires no privileges, but does require user interaction (social engineering the administrator into clicking a forged link) (GitHub Advisory, Wordfence).
Successful exploitation allows an unauthenticated attacker to delete critical WordPress options — including siteurl, home, active_plugins, template, and stylesheet — by tricking a logged-in administrator into triggering a forged request. This can result in complete site outage, forced deactivation of all plugins, or a full theme reset, effectively taking the WordPress site offline. While there is no direct confidentiality impact, the integrity impact is rated High due to the ability to corrupt core site configuration (GitHub Advisory, Wordfence).
As of the disclosure date (August 16, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering a site administrator, which raises the practical bar for attackers (GitHub Advisory, Wordfence).
readme.txt files.menu.class.php or debug_tool.php) without a valid nonce.siteurl, active_plugins, template), causing immediate site outage or plugin/theme reset (GitHub Advisory, Wordfence).wp-compress or wpc_ parameters) from unusual referrers or external domains.wp_options table, particularly for keys siteurl, home, active_plugins, template, or stylesheet.wp-content/debug.log) for errors related to missing options or plugin deactivation events coinciding with suspicious admin activity (GitHub Advisory).WordPress site administrators should update the WP Compress – Instant Performance & Speed Optimization plugin to a version newer than 7.10.09, as a patch was released on August 16, 2026 (changeset available in the WordPress plugin repository). Until an update is applied, administrators should exercise caution with unsolicited links and consider temporarily deactivating the plugin on sensitive sites. Additionally, implementing a Web Application Firewall (WAF) with CSRF protection rules and conducting security awareness training for administrators can reduce exposure (GitHub Advisory, Wordfence).
The vulnerability was reported and disclosed by Wordfence, which maintains a threat intelligence database for WordPress security issues. Coverage has been picked up by standard vulnerability aggregators including VulDB, Vulners, CIRCL, and ENISA's EUVD. No notable independent researcher commentary or significant social media discussion has been identified beyond automated CVE notification channels (Wordfence, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."