Vulnerabilities and security researches forwebp-express webp-express
Direction: ascendingJun 07, 2024
WebP Express # CVE-2019-15330
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 23, 2019
- Research Description
- The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading.
- Affected versions
-
max 0.14.11.
- Status
-
vulnerable
WebP Express # CVE-2019-15837
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 30, 2019
- Research Description
- The webp-express plugin before 0.14.8 for WordPress has stored XSS.
- Affected versions
-
max 0.14.11.
- Status
-
vulnerable
Dec 11, 2025
WebP Express # CVE-2025-11379
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 04, 2025
- Research Description
- The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and including, 0.25.9. This is due to the plugin not properly randomizing the name of the config file to prevent direct access on NGINX. This makes it possible for unauthenticated attackers to extract configuration data.
- Affected versions
-
max 0.25.11.
- Status
-
vulnerable
Jun 16, 2026
WebP Express # 9b62ca86a30d2ba360cc026cf8c7c2f018981bcb
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 16, 2019
- Research Description
- WebP Express [webp-express] < 0.14.1 WordPress WebP Express plugin <= 0.14.0 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability found in WordPress WebP Express plugin (versions <= 0.14.0).
- Affected versions
-
max 0.14.1.
- Status
-
vulnerable
WebP Express # 04da00d0e7114ed3f484a6064f3aca9889b0add2
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 26, 2019
- Research Description
- WebP Express [webp-express] < 0.14.8 WordPress WebP Express plugin <= 0.14.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by M0ns7er in WordPress WebP Express plugin (versions <= 0.14.4).
- Affected versions
-
max 0.14.8.
- Status
-
vulnerable
Aug 25, 2026
WebP Express # PSC-2026-64689
- PSC, Research URL
- Home page URL
- Application
- Date
- Aug 24, 2026
- Research Description
- Image conversion plugins process uploaded files, write derivatives, update rewrite rules, and may invoke local or remote converters. WebP Express version 0.25.15 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64689, confirming that the review focused on file access, conversion inputs, generated output paths, rewrite behavior, converter configuration, and protection of privileged settings.
- Affected versions
-
Min 0.25.15, max 0.25.15.
- Status
-
SAFE & CERTIFIED