CVE-2025-11379
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-11379 is an information exposure vulnerability in the WebP Express plugin for WordPress, affecting all versions up to and including 0.25.9. The flaw allows unauthenticated attackers to directly access plugin configuration files on NGINX-hosted WordPress sites due to insufficient randomization of config file names. It was published on December 4, 2025, and carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, ENISA EUVD).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The WebP Express plugin fails to properly randomize the name of its configuration file, meaning the file path is predictable and directly accessible over the web on NGINX servers. An unauthenticated attacker can craft a direct HTTP GET request to the known or guessable config file path, bypassing any intended access controls and retrieving configuration data without authentication (Wordfence, ENISA EUVD).

Impact

Successful exploitation allows unauthenticated remote attackers to read the WebP Express plugin's configuration data, which may include sensitive settings such as file paths, API keys, or other site-specific configuration details. The impact is limited to confidentiality — there is no integrity or availability impact. While not directly enabling remote code execution, exposed configuration data could assist attackers in further reconnaissance or targeted attacks against the WordPress installation (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WebP Express plugin (versions ≤ 0.25.9) on NGINX using tools like WPScan, Shodan, or by inspecting HTTP response headers and page source for plugin indicators.
  2. Identify config file path: Determine the predictable (non-randomized) path to the WebP Express configuration file within the WordPress installation directory (e.g., under wp-content/plugins/webp-express/).
  3. Direct file access: Send an unauthenticated HTTP GET request to the known config file URL (e.g., https://target.com/wp-content/plugins/webp-express/<config-filename>) on the NGINX-hosted site.
  4. Extract configuration data: Parse the returned response to extract configuration details such as file paths, conversion settings, or any sensitive values stored in the config file for use in further reconnaissance or targeted attacks (Wordfence).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP GET requests to WebP Express plugin configuration file paths (e.g., paths under /wp-content/plugins/webp-express/) returning HTTP 200 responses with configuration data.
  • Logs: NGINX access logs showing direct requests to WebP Express config files from unexpected or external IP addresses, particularly with no referrer header and no session cookie.
  • File System: No file system changes are expected from read-only exploitation; however, review for any unexpected access patterns to plugin directories.

Mitigation and workarounds

Users should update the WebP Express plugin to a version beyond 0.25.9 that addresses the config file name randomization issue. As a workaround on NGINX, administrators can add explicit deny all rules in the NGINX configuration to block direct web access to the plugin's configuration file directory. Regularly auditing NGINX access logs for unexpected requests to plugin directories is also recommended (Wordfence, WordPress Plugin Page).

Community reactions

The vulnerability was reported and assigned by Wordfence, which published the advisory in its threat intelligence database. There is limited broader community discussion, with some automated CVE tracking accounts on Bluesky and Mastodon noting the disclosure. No significant vendor statements or major media coverage have been identified beyond the initial Wordfence advisory (Wordfence).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13147CRITICAL9.1
  • kirki
NoYesJul 20, 2026
CVE-2026-9833HIGH7.1
  • tag-groups
NoYesJul 20, 2026
CVE-2026-13432MEDIUM5.4
  • image-sizes
NoYesJul 20, 2026
CVE-2026-13156MEDIUM5.4
  • mailersend-official-smtp-integration
NoYesJul 20, 2026
CVE-2026-8825MEDIUM4.9
  • elementor
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management