VYPR
Unrated severityNVD Advisory· Published Mar 25, 2025· Updated Apr 8, 2026

WP Compress <= 6.30.15 - Unauthenticated Server-Side Request Forgery via init Function

CVE-2025-2109

Description

An unauthenticated SSRF vulnerability in WP Compress up to v6.30.15 allows attackers to probe internal services via the plugin's init() function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated SSRF vulnerability in WP Compress up to v6.30.15 allows attackers to probe internal services via the plugin's init() function.

Vulnerability

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in all versions up to, and including, 6.30.15. The flaw resides in the init() function, which processes user-supplied input to make web requests to arbitrary locations without proper validation or restriction. This condition makes the code path reachable by any unauthenticated visitor. [1]

Exploitation

An unauthenticated attacker can trigger the vulnerability by sending a crafted request to the vulnerable endpoint that invokes the init() function. The attacker specifies a target URL (e.g., an internal service like http://localhost or http://192.168.x.x) as part of the request parameters. The plugin then makes an HTTP request from the web server’s context to that arbitrary location. No special privileges, user interaction, or network position other than standard web access is required. [1]

Impact

Successful exploitation allows an attacker to perform Server-Side Request Forgery, enabling them to make HTTP requests from the vulnerable WordPress server to any internal or external destination. This can be used to probe and potentially interact with internal services (e.g., cloud metadata endpoints, databases, or other containerized services) that are not intended to be exposed externally. The attacker can leverage this to gather sensitive information or prepare further attacks. [1]

Mitigation

The plugin vendor has released version 7.00.08 (last updated 2026-04-15), which presumably addresses this vulnerability. Users should update immediately to the latest version. No workarounds are provided in the available references. For installations where updating is not possible, consider restricting outbound HTTP requests from the web server via firewall rules or disabling the plugin. [1]

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.