PT-2025-49003 · WordPress · Webp-Express

Rafshanzani Suhada

·

Published

2025-12-04

·

Updated

2025-12-04

·

CVE-2025-11379

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WebP Express versions prior to 0.25.9
Description The WebP Express plugin for WordPress is susceptible to information disclosure through improperly randomized config file names when used with NGINX. This allows unauthenticated attackers to extract configuration data. The plugin does not properly randomize the name of the config file, enabling direct access.
Recommendations Update the WebP Express plugin to a version newer than 0.25.9.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-11379

Affected Products

Webp-Express