What is CVE-2026-9066?
A Reflected XSS vulnerability exists in the WP Compress WordPress plugin before version 7.10.04 due to insufficient validation of a query parameter controlling the asset CDN host. An attacker can inject malicious JavaScript into generated URLs, which executes when a victim follows a crafted link. Updating the plugin to the latest version mitigates this issue.
Azərbaycanca: WP Compress WordPress plaginində (7.10.04-dən əvvəlki versiyalar) "Reflected XSS" zəifliyi aşkarlanıb. Təcavüzkar asset CDN hostunu idarə edən sorğu parametrini manipulyasiya edərək səhifədə zərərli JavaScript kodu icra edə bilər. İstismar üçün istifadəçinin xüsusi hazırlanmış linki izləməsi tələb olunur. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the WP Compress plugin are affected by CVE-2026-9066?
This Reflected XSS vulnerability affects the WP Compress plugin versions prior to 7.10.04.
What does an attacker need to do to exploit CVE-2026-9066?
An attacker must manipulate a query parameter that controls the asset CDN host to inject malicious JavaScript into a crafted link. Exploitation requires a user to follow this crafted link.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.