CVE-2025-2110
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 862
Summary
CVE-2025-2110 is a vulnerability affecting the WP Compress plugin for WordPress. This issue, present in all versions up to 6.30.15, exposes the plugin to unauthorized access, modification, and data loss due to insufficient capability checks on its AJAX functions. Authenticated attackers with Subscriber-level access or higher can exploit this vulnerability to retrieve sensitive information, disrupt plugin functionality, or alter and delete settings, potentially affecting overall site performance.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.