Converter for Media – Optimize images | Convert WebP & AVIF <= 6.5.1 - Unauthenticated Server-Side Request Forgery via src
medium
The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.5.1 via the PassthruLoader::load_image_source function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locatio...
- CVSS:
- 4.8
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.2
- Disclosed:
- Feb 11, 2026
CVE-2026-1356 on NVD →
Converter for Media – Optimize images | Convert WebP & AVIF [webp-converter-for-media] < 6.4.0
unknown
[en] The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `/webp-converter/v1/regenerate-attachment` REST endpoint in all versions up to, and including, 6.3.2. This makes it possible for authentic...
- Affected:
- up to 6.4.0
- Fixed in:
- 6.4.0
- Disclosed:
- Dec 17, 2025
CVE-2025-13750 on NVD →
Converter for Media <= 6.3.2 - Missing Authorization to Authenticated (Subscriber+) Optimized Image Deletion via regenerate-attachment REST Endpoint
medium
The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `/webp-converter/v1/regenerate-attachment` REST endpoint in all versions up to, and including, 6.3.2. This makes it possible for authenticated...
- CVSS:
- 4.3
- Affected:
- up to 6.3.2
- Fixed in:
- 6.4.0
- Disclosed:
- Dec 16, 2025
CVE-2025-13750 on NVD →
WebP Converter for Media <= 4.0.2 - Unauthenticated Open Redirect
medium
The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue
- CVSS:
- 6.1
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.3
- Disclosed:
- Dec 27, 2021
CVE-2021-25074 on NVD →
Converter for Media – Optimize images | Convert WebP & AVIF [webp-converter-for-media] < 1.0.3
unknown
[en] The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.3
- Disclosed:
- Aug 30, 2019
CVE-2019-15834 on NVD →
WebP Converter for Media – Convert WebP and AVIF & Optimize Images <= 1.0.2 - Cross-Site Request Forgery
high
The WebP Converter for Media – Convert WebP and AVIF & Optimize Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to gain otherwise restricted access...
- CVSS:
- 8.8
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.3
- Disclosed:
- Jun 27, 2019
CVE-2019-15834 on NVD →
Converter for Media – Optimize images | Convert WebP & AVIF [webp-converter-for-media] < 1.0.3
unknown
Cross-Site Request Forgery (CSRF) vulnerability found WordPress WebP Converter for Media plugin (versions <= 1.0.2).
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.3
- Disclosed:
- Jun 27, 2019
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database