What is CVE-2026-17608?
CVE-2026-17608 affects the WP Compress plugin for WordPress up to version 7.10.09, allowing Cross-Site Request Forgery (CSRF) due to missing nonce validation. Unauthenticated attackers could exploit this to perform unauthorized actions. Users should update the plugin or disable it if no patch is available.
Azərbaycanca: CVE-2026-17608, WordPress üçün WP Compress plaginində (versiya 7.10.09 daxil olmaqla) aşkarlanıb. Bu zəiflik nonce yoxlamasının olmaması səbəbindən Cross-Site Request Forgery (CSRF) hücumlarına imkan verir. İstifadəçilər plaqini ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which plugin and version are affected by CVE-2026-17608?
This vulnerability affects the WP Compress plugin for WordPress up to version 7.10.09.
What is the main cause of CVE-2026-17608?
The main cause of the vulnerability is missing nonce validation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.