CVE-2026-17608

WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Deletion

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or incorrect nonce validation on the (top-level template code) function. This makes it possible for unauthenticated attackers to delete arbitrary WordPress options, including critical ones such as siteurl, home, active_plugins, template, and stylesheet, causing site outage or a full plugin and theme reset via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.


We have discovered 1,043 live websites that are affected by CVE-2026-17608.

Run a Free Instant Scan




Affected Software

Product  Wp Compress Image Optimizer
Category Wordpress Plugins
Vulnerable Domains1,043 live websites (100% of Wp Compress Image Optimizer install base)
Vulnerable Versions
  • from 0 through 7.10.9
Vulnerable Versions Count73 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Aug 16, 2026
  • Updated - Aug 18, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-17608
United States342 websites



Germany167 websites
France58 websites
Netherlands57 websites
India44 websites
GB41 websites
Czech Republic40 websites
Canada35 websites
Italy28 websites
Switzerland24 websites

Website Distribution by TLD

Number of websites using CVE-2026-17608
.com463 websites
.de126 websites
.nl54 websites
.cz36 websites
.org27 websites
.co.uk21 websites
.net20 websites
.ch19 websites
.fr19 websites
.com.au16 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-17608

Top websites that are affected by CVE-2026-17608. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com Germany**,***
**************.com United States**,***
********.org Italy***,***
*************.com France***,***
***************.fr France***,***
****.com India***,***
*************.com United States***,***
*************.com United States***,***
**********.com United States***,***
***********************.de Germany***,***
See full domain list

FAQ

CVE-2026-17608 is Cross-Site Request Forgery (CSRF) in Wp Compress Image Optimizer
A total of 1,043 websites have been identified as vulnerable to CVE-2026-17608, based on global website indexing conducted by WebTechSurvey.
The Wp Compress Image Optimizer is affected by the CVE-2026-17608 vulnerability.
Wp Compress Image Optimizer versions up to and including 7.10.9 are vulnerable to CVE-2026-17608.

References