
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11379 is an information exposure vulnerability in the WebP Express plugin for WordPress, affecting all versions up to and including 0.25.9. The flaw allows unauthenticated attackers to directly access plugin configuration files on NGINX-hosted WordPress sites due to insufficient randomization of config file names. It was published on December 4, 2025, and carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, ENISA EUVD).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The WebP Express plugin fails to properly randomize the name of its configuration file, meaning the file path is predictable and directly accessible over the web on NGINX servers. An unauthenticated attacker can craft a direct HTTP GET request to the known or guessable config file path, bypassing any intended access controls and retrieving configuration data without authentication (Wordfence, ENISA EUVD).
Successful exploitation allows unauthenticated remote attackers to read the WebP Express plugin's configuration data, which may include sensitive settings such as file paths, API keys, or other site-specific configuration details. The impact is limited to confidentiality — there is no integrity or availability impact. While not directly enabling remote code execution, exposed configuration data could assist attackers in further reconnaissance or targeted attacks against the WordPress installation (Wordfence).
wp-content/plugins/webp-express/).https://target.com/wp-content/plugins/webp-express/<config-filename>) on the NGINX-hosted site./wp-content/plugins/webp-express/) returning HTTP 200 responses with configuration data.Users should update the WebP Express plugin to a version beyond 0.25.9 that addresses the config file name randomization issue. As a workaround on NGINX, administrators can add explicit deny all rules in the NGINX configuration to block direct web access to the plugin's configuration file directory. Regularly auditing NGINX access logs for unexpected requests to plugin directories is also recommended (Wordfence, WordPress Plugin Page).
The vulnerability was reported and assigned by Wordfence, which published the advisory in its threat intelligence database. There is limited broader community discussion, with some automated CVE tracking accounts on Bluesky and Mastodon noting the disclosure. No significant vendor statements or major media coverage have been identified beyond the initial Wordfence advisory (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."