CRITICAL🇵🇱 Wersja polska

CVE-2023-6699

CVSS 9.1v3.1pub. 2024-01-11upd. 2026-04-08

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

🤖 AI Analysis
How it works

An attacker sends a specially crafted HTTP request containing path traversal sequences (e.g., '../') in the 'css' parameter, which allow escaping the permitted directory and pointing to any file in the server's file system. The plugin does not properly validate the provided path, resulting in reading and returning the contents of the specified file. Since the attack does not require authentication, any network user can perform it.

Impact

An attacker can read the contents of any files accessible to the web server process, including WordPress configuration files (e.g., wp-config.php with database credentials), private keys, passwords, and other sensitive data stored on the server.

Mitigation & patch

The WP Compress – Image Optimizer plugin should be updated to a version higher than 6.10.33, which introduces a fix for CSS parameter validation. The update can be performed directly from the WordPress admin panel or downloaded from the official plugin repository.

Who is affected

WP Compress – Image Optimizer [All-In-One] plugin for WordPress in all versions up to and including 6.10.33.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Wpcompress Wp Compress

    APP
    Wpcompress
    ≤ 6.10.33
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path TraversalAuth Bypass
CWE
References

Related vulnerabilities

CVE-2025-47546HIGH7.1same product

Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Cross...

CVE-2025-2110HIGH8.8same product

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized ...

CVE-2024-47384HIGH7.1same product

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AresIT W...

CVE-2024-1934HIGH7.5same product

The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due ...

CVE-2025-47479MEDIUM5.3same product

Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abus...