plugin

Webp Converter For Media Vulnerabilities

7 known security issues reported for the Webp Converter For Media WordPress plugin. Most recent disclosed Feb 11, 2026.

1 high 3 medium

Running Webp Converter For Media on your site? Check whether your installed version is affected.

Scan your site free

Converter for Media – Optimize images | Convert WebP & AVIF <= 6.5.1 - Unauthenticated Server-Side Request Forgery via src

medium

The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.5.1 via the PassthruLoader::load_image_source function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locatio...

CVSS:
4.8
Affected:
up to 6.5.1
Fixed in:
6.5.2
Disclosed:
Feb 11, 2026

CVE-2026-1356 on NVD →

Converter for Media &#8211; Optimize images | Convert WebP &amp; AVIF [webp-converter-for-media] < 6.4.0

unknown

[en] The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `/webp-converter/v1/regenerate-attachment` REST endpoint in all versions up to, and including, 6.3.2. This makes it possible for authentic...

Affected:
up to 6.4.0
Fixed in:
6.4.0
Disclosed:
Dec 17, 2025

CVE-2025-13750 on NVD →

Converter for Media <= 6.3.2 - Missing Authorization to Authenticated (Subscriber+) Optimized Image Deletion via regenerate-attachment REST Endpoint

medium

The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `/webp-converter/v1/regenerate-attachment` REST endpoint in all versions up to, and including, 6.3.2. This makes it possible for authenticated...

CVSS:
4.3
Affected:
up to 6.3.2
Fixed in:
6.4.0
Disclosed:
Dec 16, 2025

CVE-2025-13750 on NVD →

WebP Converter for Media <= 4.0.2 - Unauthenticated Open Redirect

medium

The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue

CVSS:
6.1
Affected:
up to 4.0.3
Fixed in:
4.0.3
Disclosed:
Dec 27, 2021

CVE-2021-25074 on NVD →

Converter for Media &#8211; Optimize images | Convert WebP &amp; AVIF [webp-converter-for-media] < 1.0.3

unknown

[en] The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.

Affected:
up to 1.0.3
Fixed in:
1.0.3
Disclosed:
Aug 30, 2019

CVE-2019-15834 on NVD →

WebP Converter for Media – Convert WebP and AVIF & Optimize Images <= 1.0.2 - Cross-Site Request Forgery

high

The WebP Converter for Media – Convert WebP and AVIF & Optimize Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to gain otherwise restricted access...

CVSS:
8.8
Affected:
up to 1.0.2
Fixed in:
1.0.3
Disclosed:
Jun 27, 2019

CVE-2019-15834 on NVD →

Converter for Media &#8211; Optimize images | Convert WebP &amp; AVIF [webp-converter-for-media] < 1.0.3

unknown

Cross-Site Request Forgery (CSRF) vulnerability found WordPress WebP Converter for Media plugin (versions <= 1.0.2).

Affected:
up to 1.0.3
Fixed in:
1.0.3
Disclosed:
Jun 27, 2019

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database