Summary
CVE-2026-73343 is a critical unauthenticated Remote Code Execution (RCE) vulnerability in the WP Compress WordPress plugin (wp-compress-image-optimizer) developed by AresIT. The flaw is classified as CWE-94 (Improper Control of Generation of Code / Code Injection) and carries a maximum CVSS v3.1 base score of 10.0. It affects all WP Compress plugin versions prior to 7.20.01.
Technical details
- Root cause: improper control of code generation within the plugin, classified under CWE-94 (Code Injection), enabling execution of attacker-supplied code (CAPEC-253: Remote Code Inclusion).
- Trigger conditions: no authentication or user interaction is required to exploit the vulnerability.
- Attack vector: Network — the plugin’s exposed functionality can be reached remotely over HTTP(S) on any WordPress site running the vulnerable plugin version.
- Impact: full compromise of confidentiality, integrity, and availability of the affected WordPress site, consistent with arbitrary code execution on the underlying server.
Affected software
- WP Compress (wp-compress-image-optimizer) WordPress plugin, developed by AresIT
- All versions prior to 7.20.01
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade the WP Compress plugin to version 7.20.01 or later, where the vulnerability has been fixed.
- If immediate patching is not possible: disable and remove the WP Compress plugin from affected WordPress installations until the update can be applied. There is no documented network-level workaround for this issue, so patching remains the primary remediation path.
How IONIX identifies potentially affected assets
IONIX matches the following signal against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/wp-content/plugins/wp-compress-image-optimizer/

