Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly: from n/a through <= 3.2.7.
Published: 2026-05-27
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The QuickWebP plugin for WordPress contains a Path Traversal flaw (CWE‑22) that allows an attacker who can send crafted HTTP requests to the plugin’s file handling endpoints to delete any file on the server. The vulnerability is not limited to file uploads; any user who can trigger the plugin’s internal operations can specify a relative path that escapes the intended directory, leading to loss of critical data. The flaw is rated CVSS 9.9, indicating that an attacker who succeeds could cause significant damage and potentially compromise the entire WordPress installation.

Affected Systems

WordPress sites running Ludwig You QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly with version 3.2.7 or earlier are affected. The vulnerability does not apply to newer plugin releases. Administrators should verify the current plugin version by checking the Plugins page in the WordPress dashboard.

Risk and Exploitability

The CVSS score of 9.9 categorizes the vulnerability as Critical. There is no EPSS value provided, but the lack of a mitigation and the remote nature of the flaw suggest a high likelihood of exploitation. The flaw is not listed in CISA KEV, but the severity alone warrants immediate action. Attackers can simply send a request to the plugin’s endpoint with a crafted file path; no privileged credentials are required if the attacker can access the WordPress site. Therefore, if the plugin remains installed in a vulnerable state, the risk of arbitrary file deletion across the file system is high.

Generated by OpenCVE AI on May 27, 2026 at 12:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • If an upgrade is not possible, uninstall or disable the QuickWebP plugin immediately to eliminate the risk.
  • Apply file system permissions that restrict the web server user from deleting critical application files, and use WordPress security plugins to enforce file integrity.
  • Ensure the WordPress core and all other plugins are updated to their latest secure versions.

Generated by OpenCVE AI on May 27, 2026 at 12:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 27 May 2026 10:30:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly: from n/a through <= 3.2.7.
Title WordPress QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly plugin <= 3.2.7 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-27T10:48:41.723Z

Reserved: 2026-04-29T09:05:35.592Z

Link: CVE-2026-42756

cve-icon Vulnrichment

Updated: 2026-05-27T10:48:36.582Z

cve-icon NVD

Status : Received

Published: 2026-05-27T11:16:22.100

Modified: 2026-05-27T11:16:22.100

Link: CVE-2026-42756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T12:15:05Z

Weaknesses