WP Compress – Instant Performance & Speed Optimization <= 6.30.03 - Reflected Cross-Site Scripting via custom_server Parameter
Description
WP Compress plugin ≤6.30.03 has a reflected XSS via the 'custom_server' parameter, allowing unauthenticated attackers to inject scripts that execute when a user clicks a malicious link.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
WP Compress plugin ≤6.30.03 has a reflected XSS via the 'custom_server' parameter, allowing unauthenticated attackers to inject scripts that execute when a user clicks a malicious link.
Vulnerability
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) through the custom_server parameter in all versions up to and including 6.30.03 [1]. The vulnerability stems from insufficient input sanitization and output escaping, allowing arbitrary web script injection. Affected versions include all releases prior to the patched version 7.00.08 [1].
Exploitation
An unauthenticated attacker can exploit this flaw by crafting a malicious URL containing a payload in the custom_server parameter. The attack requires user interaction: the victim must be tricked into clicking the crafted link, which triggers the reflected script execution in the context of their browser session [1]. No authentication or special network position is required for the initial injection.
Impact
Successful exploitation allows the attacker to inject arbitrary web scripts into pages generated by the plugin. This can lead to session hijacking, credential theft, defacement, or redirection to malicious sites, compromising the confidentiality and integrity of the affected WordPress installation. The attacker operates within the security context of the victim user.
Mitigation
The vendor has released version 7.00.08, which likely addresses the vulnerability; users are strongly advised to update immediately. No workarounds are documented in the available references. No known evidence of exploitation in the wild has been cited.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <=6.30.03
- aresit/WP Compress – Instant Performance & Speed Optimizationv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- plugins.trac.wordpress.org/browser/wp-compress-image-optimizer/tags/6.30.00/addons/cdn/cdn-rewrite.phpmitre
- plugins.trac.wordpress.org/changeset/3213738/mitre
- wordpress.org/plugins/wp-compress-image-optimizer/mitre
- www.wordfence.com/threat-intel/vulnerabilities/id/09c04863-a454-4f05-9403-aff39dbccd43mitre
News mentions
0No linked articles in our index yet.