CVE · Medium

CVE-2025-13750 — Converter for Media – Optimize images | Convert WebP & AVIF [webp-converter-for-media] < 6.4.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13750 Converter for Media – Optimize images | Convert WebP & AVIF [webp-converter-for-media] < 6.4.0 Missing Authorization Medium 4.3 < 6.4.0 6.4.0 2025-12-16

CVE-2025-13750

A security flaw exists in the Converter for Media plugin, affecting WordPress installations that utilize version 6.3.2 or earlier. The vulnerability arises from a lack of permission checks on a specific REST endpoint, allowing users with Subscriber-level access and above to delete optimized image files for any attachment without authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.