9.9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly: from n/a through <= 3.2.7.
AI Analysis
Path Traversal vulnerability in QuickWebP plugin allowing arbitrary file deletion
Basic Information
ID
CVE-2026-42756
Source
Patchstack
Published
May 27, 2026 at 09:49
Affected Product
Vendor
Ludwig You
Product
QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly
Affected Versions
Ludwig You QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly 0
CWE Classification
AI Assessment
AI Score
9.9 / 10
AI Severity
Critical
Vendor
Ludwig You
Product
QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly
Version
<= 3.2.7