VYPR

Webp Converter For Media

by WordPress

Source repositories

CVEs (4)

  • CVE-2019-15834HigAug 30, 2019
    risk 0.57cvss 8.8epss 0.01

    The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.

  • CVE-2021-25074MedJan 24, 2022
    risk 0.40cvss 6.1epss 0.02

    The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue

  • CVE-2026-1356MedFeb 12, 2026
    risk 0.24cvss 4.8epss 0.00

    The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.5.1 via the PassthruLoader::load_image_source function. This makes it possible for unauthenticated…

  • CVE-2025-13750MedDec 17, 2025
    risk 0.21cvss 4.3epss 0.00

    The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `/webp-converter/v1/regenerate-attachment` REST endpoint in all versions up to, and including,…