CVE 9.9 CRITICAL

WordPress QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly plugin <= 3.2.7 - Arbitrary File Deletion vulnerability_CVE-2026-42756

9.9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly: from n/a through <= 3.2.7.

AI Analysis

Path Traversal vulnerability in QuickWebP plugin allowing arbitrary file deletion

Basic Information

ID CVE-2026-42756
Source Patchstack
Published May 27, 2026 at 09:49

Affected Product

Vendor Ludwig You
Product QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly
Affected Versions Ludwig You QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly 0

CWE Classification

AI Assessment

AI Score 9.9 / 10
AI Severity Critical
Vendor Ludwig You
Product QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly
Version <= 3.2.7

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.