← back to popular plugins
wordfence / plugin · webp-express
WebP Express
webp-express
total installs
300,000
total vulns
1
critical
0
high
0
medium
1
low
0
latest vuln
—
patched
1
unpatched
0
avg time to patch
—
vulnerabilities
(1)
WebP Express <= 0.25.9 - Unauthenticated Information Exposure
medium
✓ patched
cve id
CVE-2025-11379 ↗
cvss score
5.3
cwe
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
published
Dec 3, 2025
The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and including, 0.25.9. This is due to the plugin not properly randomizing the name of the config file to prevent direct access on NGINX. This makes it possible for unauthenticated attackers to extract configuration data.