Back to overview

CVE-2026-9066

Description
The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.

Metadata

CVE ID
CVE-2026-9066
State
PUBLISHED
Assigner
WPScan
Reserved
2026-05-20 08:42 UTC
Published
2026-07-23 06:00 UTC
Last updated
2026-07-23 06:00 UTC
Vendor / Product
Unknown / WP Compress
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown WP Compress 0 < 7.10.04
Weakness (CWE)
CWESourceDescription
cna CWE-79 Cross-Site Scripting (XSS)
Back to overview