Unauthorized Data Modification in the Converter for Media Plugin by WordPress
CVE-2025-13750
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 December 2025
What is CVE-2025-13750?
The Converter for Media β Optimize images | Convert WebP & AVIF plugin for WordPress is susceptible to unauthorized data modification due to a lack of capability checks on the /webp-converter/v1/regenerate-attachment REST endpoint. This flaw permits authenticated users with Subscriber-level access and higher to delete optimized WebP and AVIF variants of attachments, posing significant security risks for WordPress sites utilizing this plugin version 6.3.2 and earlier.
Affected Version(s)
Converter for Media β Optimize images | Convert WebP & AVIF * <= 6.3.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marcin Dudek