Images to WebP < 1.9 - Authenticated Local File Inclusion
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 5.0%
from disclosure to weapon
Published on NVDNov 23
VulnCheckOct 19
exploitation probability
5.0%top 9% of all CVEs
observed exploitation
yesVulnCheck
The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue
Affected products
Unknown · Images to WebP