← back to popular plugins
wordfence / plugin · webp-express

WebP Express

webp-express
total installs
300,000
total vulns
1
critical
0
high
0
medium
1
low
0
latest vuln
patched
1
unpatched
0
avg time to patch
vulnerabilities (1)
WebP Express <= 0.25.9 - Unauthenticated Information Exposure
medium ✓ patched
cvss score 5.3
cwe CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
published Dec 3, 2025
The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and including, 0.25.9. This is due to the plugin not properly randomizing the name of the config file to prevent direct access on NGINX. This makes it possible for unauthenticated attackers to extract configuration data.