HIGH
eastsidecode
CVE published 2026-01-07
CVE-2025-15158
The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation. Authenticated attackers with Author-level access and above can upload arbitrary files, potentially leading to remote code execution. This vulnerability allows attackers to upload files that could be used to execute malicious code on the affected site, making it a high-risk issue for WordPr [truncated]