Compress & Upload WordPress Plugin Improper File Upload Validation Vulnerability (CVE-2025-8889) — Low Severity

The digital landscape relies heavily on the smooth functioning of plugins, especially within platforms like WordPress. However, sometimes these helpful tools can introduce security concerns if not designed with robust protections. We’re looking into a recent discovery concerning the “Compress & Upload” WordPress plugin.

This particular issue, identified as CVE-2025-8889, revolves around how the plugin handles file uploads. In simple terms, it didn’t check uploaded files carefully enough. This oversight meant that even highly privileged users, like an administrator, could upload files that weren’t intended, such as malicious scripts, onto the server. This could happen even in WordPress multisite environments, where stricter controls are typically expected.

CVE Details

  • Product: Compress & Upload WordPress plugin
  • CVE ID: CVE-2025-8889
  • Published: September 9, 2025
  • Severity: Low
  • Status: Analyzed

Affected Products

The vulnerability affects versions of the Compress & Upload WordPress plugin that are older than 1.0.5. If you are using any version prior to 1.0.5, your installation could be at risk.

Current Status

This vulnerability has been thoroughly analyzed. The details, including how the flaw works and its potential impact, are understood by security researchers. This vulnerability was last modified on January 28, 2026.

Severity Level

The Common Vulnerability Scoring System (CVSS) rates this vulnerability with a score of 3.8, classifying it as “Low” severity. While it requires a user with high privileges (like an administrator) to exploit, the potential to upload arbitrary files is a significant concern. In a controlled environment, an attacker would already need substantial access, limiting its broader impact compared to vulnerabilities exploitable by less privileged users. However, it’s a reminder that even trusted roles need robust security.

Possible Solutions

The good news is that a fix is available! To secure your WordPress site, it is highly recommended to update your “Compress & Upload” plugin to version 1.0.5 or newer as soon as possible. Updating to the latest version ensures that the file validation process is correctly implemented, preventing unauthorized file uploads.

References

https://wpscan.com/vulnerability/5d84a577-62aa-4aa2-ac39-b146eae65243/

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.