Junglewise Threat Intelligence

CVE-2026-42756: Ludwig You QuickWebP path traversal in quickwebp

CVE-2026-42756 · Severity: critical · CVSS 9.9 · Published 2026-05-27

Executive brief

A security vulnerability exists in QuickWebP, a WordPress plugin used to optimize and convert website images. An attacker with basic user permissions could exploit this flaw to access or delete files outside of the intended image folders. This could lead to the deletion of critical website files, potentially causing a complete site outage or data loss.

Technical details

A path traversal vulnerability (CWE-22) exists in the Ludwig You QuickWebP plugin for WordPress through version 3.2.7. The vulnerability stems from improper limitation of pathnames within the 'quickwebp' component, which fails to adequately sanitize user-supplied input used in file operations. An attacker with low-level authenticated access (Subscriber or higher) can provide manipulated file paths to reach directories outside the intended scope. According to the advisory details, this specific path traversal flaw can be leveraged to achieve arbitrary file deletion, potentially leading to a full site compromise or denial of service.

Affected products

  • Ludwig You QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly <= 3.2.7

Timeline

  • 2026-05-27: advisory: NVD and Patchstack published the vulnerability details.

References