{"id":"CVE-2025-13750","title":"The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `/webp-converter/v1/regenerate-attachment` REST endpoint in …","summary":"The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `/webp-converter/v1/regenerate-attachment` REST endpoint in …","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"published":"2025-12-17","updated":"2026-09-28","sourceUpdated":"2026-09-28T10:10:00.473","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-13750","references":[{"url":"https://plugins.trac.wordpress.org/changeset/3414745/webp-converter-for-media","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9a31190f-e2ed-46ee-a224-85a0a003738d?source=cve","label":"security@wordfence.com"}],"tags":["nvd"],"epss":0.00264,"epssPercentile":0.16443,"ingestedAt":"2026-09-28T11:08:06.661Z","slug":"CVE-2025-13750","body":"## Overview\n\nThe Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `/webp-converter/v1/regenerate-attachment` REST endpoint in all versions up to, and including, 6.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete optimized WebP/AVIF variants for arbitrary attachments.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}