The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
An attacker sends a specially crafted HTTP request containing path traversal sequences (e.g., '../') in the 'css' parameter, which allow escaping the permitted directory and pointing to any file in the server's file system. The plugin does not properly validate the provided path, resulting in reading and returning the contents of the specified file. Since the attack does not require authentication, any network user can perform it.
An attacker can read the contents of any files accessible to the web server process, including WordPress configuration files (e.g., wp-config.php with database credentials), private keys, passwords, and other sensitive data stored on the server.
The WP Compress – Image Optimizer plugin should be updated to a version higher than 6.10.33, which introduces a fix for CSS parameter validation. The update can be performed directly from the WordPress admin panel or downloaded from the official plugin repository.
WP Compress – Image Optimizer [All-In-One] plugin for WordPress in all versions up to and including 6.10.33.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NWpcompress Wp Compress
APPWpcompress≤ 6.10.33
Related vulnerabilities
Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Cross...
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized ...
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AresIT W...
The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due ...
Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abus...