The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or incorrect nonce validation on the (top-level template code) function. This makes it possible for unauthenticated attackers to delete arbitrary WordPress options, including critical ones such as siteurl, home, active_plugins, template, and stylesheet, causing site outage or a full plugin and theme reset via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 1,043 live websites that are affected by CVE-2026-17608.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,043 live websites (100% of Wp Compress Image Optimizer install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 73 versions ( 100% of all versions) |
| 342 websites | |
| 167 websites | |
| 58 websites | |
| 57 websites | |
| 44 websites | |
| 41 websites | |
| 40 websites | |
| 35 websites | |
| 28 websites | |
| 24 websites |
| .com | 463 websites |
| .de | 126 websites |
| .nl | 54 websites |
| .cz | 36 websites |
| .org | 27 websites |
| .co.uk | 21 websites |
| .net | 20 websites |
| .ch | 19 websites |
| .fr | 19 websites |
| .com.au | 16 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.com | **,*** | ||
| **************.com | **,*** | ||
| ********.org | ***,*** | ||
| *************.com | ***,*** | ||
| ***************.fr | ***,*** | ||
| ****.com | ***,*** | ||
| *************.com | ***,*** | ||
| *************.com | ***,*** | ||
| **********.com | ***,*** | ||
| ***********************.de | ***,*** |
FAQ