The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Thu, 23 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 23 Jul 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpcompress Wpcompress wp Compress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpcompress Wpcompress wp Compress |
Thu, 23 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site. | |
| Title | WP Compress < 7.10.04 - Reflected XSS via test_zone | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-23T14:11:13.014Z
Reserved: 2026-05-20T08:42:05.343Z
Link: CVE-2026-9066
Updated: 2026-07-23T14:09:20.467Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-23T08:15:03Z