CVE-2026-73343 is the one CVE in this batch where NVD states the severe outcome outright rather than leaving it to inference: the record describes unauthenticated remote code execution in WP Compress, a WordPress performance and image-optimisation plugin, in versions before 7.20.01. NVD scores it 10.0 and classifies it as CWE-94 (Improper Control of Generation of Code). VulnCheck’s KEV feed reports it as exploited, dated August 18, 2026.
The exploitation report is single-sourced, as with the rest of this batch. CISA has not added CVE-2026-73343 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 16, 2026, so no Binding Operational Directive 26-04 obligation follows. VulnCheck’s catalog admits exploitation evidence on broader criteria than CISA’s; a listing there is a reported-exploitation signal, not a federal mandate.
What the flaw is
CWE-94 is code injection proper — the application constructs code that it then executes, and an attacker can influence what that code says. It is distinct from the SQL injection and deserialization classes elsewhere in this collection: there is no intermediate interpreter to escape and no gadget chain to assemble, because the defect hands attacker-influenced input directly to a code-execution path. That directness is why NVD’s own description reaches “unauthenticated remote code execution” as a bare statement of effect rather than describing a precondition and leaving the consequence open.
NVD does not identify which component or code path is responsible, and no second ingested source does either. What our evidence establishes is the weakness class, the unauthenticated precondition, the outcome, and the version boundary — not the mechanism.
The version boundary is unusually clear
NVD’s description sets the affected range as versions before 7.20.01, which means 7.20.01 is the first release outside the affected range. That is a more actionable statement than the other two plugin CVEs in this batch offer — for both CVE-2026-82222 and CVE-2026-82970, NVD names an affected ceiling without implying what fixes it, and our data carries no fixed-version field at all.
Two caveats keep this honest. Our ingested data has no structured fixed_version field for this CVE either; the 7.20.01 boundary is read from NVD’s description text, which is a reliable but textual source. And an affected range expressed as “before 7.20.01” establishes that 7.20.01 is outside the range, not that it is the release the vendor shipped as the fix or that no later regression exists. Confirm against the Patchstack database entry NVD links, or the vendor’s own changelog, before treating an upgrade as complete.
Evidence and confidence
- Medium confidence — the CVSS 10.0 score, the vector (
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), the CWE-94 classification, the unauthenticated-RCE characterisation, and the 7.20.01 version boundary, all traced to NVD alone; and the exploitation report, traced to VulnCheck KEV alone. - Unknown — exploitation probability. No EPSS score has been ingested for this CVE.
No field in this record is in conflict between sources. Two gaps are worth stating because they are gaps in our pipeline rather than in the public record: no GitHub Advisory Database row has been ingested for this CVE despite one existing publicly, and our provenance shows a vendor string of wpcompress where at least some third-party trackers attribute the plugin to a differently-named publisher. Neither affects the technical claims above, but an asset inventory keyed on vendor name may not match cleanly.
Why this matters
Performance and image-optimisation plugins are installed for reasons that have nothing to do with security and are rarely revisited afterwards. They also tend to be added by whoever was optimising the site at the time, which means they frequently outlast the person who installed them — a plugin nobody remembers choosing is a plugin nobody is tracking advisories for. An unauthenticated code-execution path in that category of software is worse than its download count suggests.
The priority argument here does not need the exploitation report to carry it. Unauthenticated remote code execution, stated as such by NVD, on a plugin running with the site’s full privileges, is sufficient grounds to upgrade now. The VulnCheck listing adds urgency and it is real sourcing, but it is uncorroborated, and a defender who patches only what CISA has listed will be late on this one while a defender who patches on severity will not.
Read across the batch, the pattern is structural rather than coincidental. Three plugins from three unrelated vendors — a donation platform, a consent banner, and an image optimiser — produced maximum-severity CVEs inside a fortnight, all with identical CVSS vectors, all reported exploited by VulnCheck, none CISA-listed. The shared factor is the execution model: a WordPress plugin runs inside the site’s own PHP process with the site’s privileges, so any plugin bug that reaches code execution produces the same scope-changed assessment regardless of what the plugin does. The weakness classes differ; the blast radius does not.
Frequently Asked Questions
What is CVE-2026-73343? A CVSS 10.0 code-injection vulnerability (CWE-94) in the WP Compress WordPress plugin that, per NVD, allows unauthenticated remote code execution in versions before 7.20.01.
Is CVE-2026-73343 being actively exploited? VulnCheck’s KEV feed reports it as exploited, dated August 18, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 16, 2026 ingestion, and we have no independent corroboration. Treat it as reported exploitation rather than confirmed.
Which version should I upgrade to? NVD sets the affected range as versions before 7.20.01, so 7.20.01 is the first release outside it. Our data carries no structured fixed-version field, so confirm against the vendor changelog or the linked Patchstack entry before considering the upgrade complete.
Does this CVE create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed. The severity case stands independently.
Is authentication required? No. NVD’s vector records no required privileges and no required user interaction, and its description characterises the outcome as unauthenticated remote code execution.
How does this differ from the other two plugin CVEs published alongside it? Weakness class and evidence quality. This one is code injection with NVD stating remote code execution directly and naming a version boundary; CVE-2026-82222 is deserialization where NVD stops at object injection, and CVE-2026-82970 is unrestricted file upload. All three carry the same CVSS 10.0 vector.
Severity, vector, weakness classification, affected-version boundary, and description sourced from the National Vulnerability Database record for CVE-2026-73343. Exploitation status and the August 18, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 16, 2026. Advisory reference linked from NVD: Patchstack database entry. Aggregated September 17, 2026. See more vulnerability intelligence.