{"error":0,"message":null,"data":{"name":"Converter for Media &#8211; Optimize images | Convert WebP &amp; AVIF","plugin":"webp-converter-for-media","link":"https:\/\/wordpress.org\/plugins\/webp-converter-for-media\/","latest":"1787091660","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"09d65e404357a869d38c482bca7188561470fdb161fd59f773531c90ed8a56fe","name":"Converter for Media &#8211; Optimize images | Convert WebP &amp; AVIF [webp-converter-for-media] < 1.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15834","name":"CVE-2019-15834","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15834","description":"[en] The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.","date":"2019-08-30"},{"id":"65483794-f22f-41c7-b286-fd70c38ae160","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/65483794-f22f-41c7-b286-fd70c38ae160","description":null,"date":null},{"id":"cde5ce3fca5d2c485303ec1e821de5cedc603bbb","name":"WebP Converter for Media \u2013 Convert WebP and AVIF & Optimize Images <= 1.0.2 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/webp-converter-for-media\/webp-converter-for-media-convert-webp-and-avif-optimize-images-102-cross-site-request-forgery","description":"The WebP Converter for Media \u2013 Convert WebP and AVIF & Optimize Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2019-06-27"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"6e89637e6d14f00288d285a73774158d35ae089a13df5ee743ff8071e6dba028","name":"Converter for Media &#8211; Optimize images | Convert WebP &amp; AVIF [webp-converter-for-media] < 1.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bc13dd5a6a9cb0c7c56343d8dde09ae9eaa4d43b","name":"WordPress WebP Converter for Media plugin <= 1.0.2 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/webp-converter-for-media\/vulnerability\/wordpress-webp-converter-for-media-plugin-1-0-2-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability found WordPress WebP Converter for Media plugin (versions <= 1.0.2).","date":"2019-06-27"}],"impact":[]},{"uuid":"e81542dc2e90908c4f4c262a5264ae139449ae4d8d644ba7e27a3c2920d1ab39","name":"Converter for Media &#8211; Optimize images | Convert WebP &amp; AVIF [webp-converter-for-media] < 6.4.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.4.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13750","name":"CVE-2025-13750","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13750","description":"[en] The Converter for Media \u2013 Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `\/webp-converter\/v1\/regenerate-attachment` REST endpoint in all versions up to, and including, 6.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete optimized WebP\/AVIF variants for arbitrary attachments.","date":"2025-12-17"},{"id":"5deb19a9ed7ef6f3f22aba513a5ac4606d94fe63","name":"Converter for Media <= 6.3.2 - Missing Authorization to Authenticated (Subscriber+) Optimized Image Deletion via regenerate-attachment REST Endpoint","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/webp-converter-for-media\/converter-for-media-632-missing-authorization-to-authenticated-subscriber-optimized-image-deletion-via-regenerate-attachment-rest-endpoint","description":"The Converter for Media \u2013 Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `\/webp-converter\/v1\/regenerate-attachment` REST endpoint in all versions up to, and including, 6.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete optimized WebP\/AVIF variants for arbitrary attachments.","date":"2025-12-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"bb54d03c84b3315565baea67f843fe476c18938480c8998095101deb5a7e1f72","name":"Converter for Media &#8211; Optimize images | Convert WebP &amp; AVIF [webp-converter-for-media] < 6.5.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1356","name":"Converter for Media \u2013 Optimize images | Convert WebP & AVIF <= 6.5.1 - Unauthenticated Server-Side Request Forgery via src","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1356","description":"The Converter for Media \u2013 Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.5.1 via the PassthruLoader::load_image_source function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.","date":"0000-00-00"},{"id":"2aaddb9dd2b1b861515125d24b3f0f141dc2ea8b","name":"Converter for Media \u2013 Optimize images | Convert WebP & AVIF <= 6.5.1 - Unauthenticated Server-Side Request Forgery via src","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/webp-converter-for-media\/converter-for-media-optimize-images-convert-webp-avif-651-unauthenticated-server-side-request-forgery-via-src","description":"The Converter for Media \u2013 Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.5.1 via the PassthruLoader::load_image_source function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.","date":"2026-02-11"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1776158424"}