Images to WebP < 1.9 - Authenticated Local File Inclusion
The plugin does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue
Proof of Concept
Assuming WordPress installed at C:\xampp\htdocs\wordpress,
This will execute php_file.php at C:\xampp, outside the web-exposed directory.