VYPR
Unrated severityNVD Advisory· Published Jan 4, 2025· Updated Apr 8, 2026

WP Compress – Instant Performance & Speed Optimization <= 6.30.03 - Reflected Cross-Site Scripting via custom_server Parameter

CVE-2024-12047

Description

WP Compress plugin ≤6.30.03 has a reflected XSS via the 'custom_server' parameter, allowing unauthenticated attackers to inject scripts that execute when a user clicks a malicious link.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

WP Compress plugin ≤6.30.03 has a reflected XSS via the 'custom_server' parameter, allowing unauthenticated attackers to inject scripts that execute when a user clicks a malicious link.

Vulnerability

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) through the custom_server parameter in all versions up to and including 6.30.03 [1]. The vulnerability stems from insufficient input sanitization and output escaping, allowing arbitrary web script injection. Affected versions include all releases prior to the patched version 7.00.08 [1].

Exploitation

An unauthenticated attacker can exploit this flaw by crafting a malicious URL containing a payload in the custom_server parameter. The attack requires user interaction: the victim must be tricked into clicking the crafted link, which triggers the reflected script execution in the context of their browser session [1]. No authentication or special network position is required for the initial injection.

Impact

Successful exploitation allows the attacker to inject arbitrary web scripts into pages generated by the plugin. This can lead to session hijacking, credential theft, defacement, or redirection to malicious sites, compromising the confidentiality and integrity of the affected WordPress installation. The attacker operates within the security context of the victim user.

Mitigation

The vendor has released version 7.00.08, which likely addresses the vulnerability; users are strongly advised to update immediately. No workarounds are documented in the available references. No known evidence of exploitation in the wild has been cited.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.