plugin

Quickwebp Vulnerabilities

1 known security issue reported for the Quickwebp WordPress plugin. Most recent disclosed May 20, 2026.

1 high

Running Quickwebp on your site? Check whether your installed version is affected.

Scan your site free

QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly <= 3.2.7 - Authenticated (Contributor+) Arbitrary File Deletion

high

The QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to del...

CVSS:
8.1
Affected:
up to 3.2.7
Fixed in:
3.2.8
Disclosed:
May 20, 2026

CVE-2026-42756 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database