cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwebp-express webp-express

Direction: ascending
Jun 07, 2024

WebP Express # CVE-2019-15330

CVE, Research URL

CVE-2019-15330

Application

WebP Express

Date
Aug 23, 2019
Research Description
The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading.
Affected versions
max 0.14.11.
Status
vulnerable

WebP Express # CVE-2019-15837

CVE, Research URL

CVE-2019-15837

Application

WebP Express

Date
Aug 30, 2019
Research Description
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
Affected versions
max 0.14.11.
Status
vulnerable
Dec 11, 2025

WebP Express # CVE-2025-11379

CVE, Research URL

CVE-2025-11379

Application

WebP Express

Date
Dec 04, 2025
Research Description
The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and including, 0.25.9. This is due to the plugin not properly randomizing the name of the config file to prevent direct access on NGINX. This makes it possible for unauthenticated attackers to extract configuration data.
Affected versions
max 0.25.11.
Status
vulnerable
Jun 16, 2026

WebP Express # 9b62ca86a30d2ba360cc026cf8c7c2f018981bcb

Application

WebP Express

Date
Jun 16, 2019
Research Description
WebP Express [webp-express] < 0.14.1 WordPress WebP Express plugin <= 0.14.0 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability found in WordPress WebP Express plugin (versions <= 0.14.0).
Affected versions
max 0.14.1.
Status
vulnerable

WebP Express # 04da00d0e7114ed3f484a6064f3aca9889b0add2

Application

WebP Express

Date
Jun 26, 2019
Research Description
WebP Express [webp-express] < 0.14.8 WordPress WebP Express plugin <= 0.14.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by M0ns7er in WordPress WebP Express plugin (versions <= 0.14.4).
Affected versions
max 0.14.8.
Status
vulnerable
Aug 25, 2026

WebP Express # PSC-2026-64689

PSC, Research URL

PSC-2026-64689

Application

WebP Express

Date
Aug 24, 2026
Research Description
Image conversion plugins process uploaded files, write derivatives, update rewrite rules, and may invoke local or remote converters. WebP Express version 0.25.15 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64689, confirming that the review focused on file access, conversion inputs, generated output paths, rewrite behavior, converter configuration, and protection of privileged settings.
Affected versions
Min 0.25.15, max 0.25.15.
Status
SAFE & CERTIFIED