The digital landscape relies heavily on the smooth functioning of plugins, especially within platforms like WordPress. However, sometimes these helpful tools can introduce security concerns if not designed with robust protections. We’re looking into a recent discovery concerning the “Compress & Upload” WordPress plugin.
This particular issue, identified as CVE-2025-8889, revolves around how the plugin handles file uploads. In simple terms, it didn’t check uploaded files carefully enough. This oversight meant that even highly privileged users, like an administrator, could upload files that weren’t intended, such as malicious scripts, onto the server. This could happen even in WordPress multisite environments, where stricter controls are typically expected.
CVE Details
- Product: Compress & Upload WordPress plugin
- CVE ID: CVE-2025-8889
- Published: September 9, 2025
- Severity: Low
- Status: Analyzed
Affected Products
The vulnerability affects versions of the Compress & Upload WordPress plugin that are older than 1.0.5. If you are using any version prior to 1.0.5, your installation could be at risk.
Current Status
This vulnerability has been thoroughly analyzed. The details, including how the flaw works and its potential impact, are understood by security researchers. This vulnerability was last modified on January 28, 2026.
Severity Level
The Common Vulnerability Scoring System (CVSS) rates this vulnerability with a score of 3.8, classifying it as “Low” severity. While it requires a user with high privileges (like an administrator) to exploit, the potential to upload arbitrary files is a significant concern. In a controlled environment, an attacker would already need substantial access, limiting its broader impact compared to vulnerabilities exploitable by less privileged users. However, it’s a reminder that even trusted roles need robust security.
Possible Solutions
The good news is that a fix is available! To secure your WordPress site, it is highly recommended to update your “Compress & Upload” plugin to version 1.0.5 or newer as soon as possible. Updating to the latest version ensures that the file validation process is correctly implemented, preventing unauthorized file uploads.
References
https://wpscan.com/vulnerability/5d84a577-62aa-4aa2-ac39-b146eae65243/


