
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11693 is a Sensitive Information Exposure vulnerability in the Export WP Page to Static HTML & PDF plugin for WordPress (also known as "Export WP Pages to HTML & PDF – Simply Create a Static Website"), developed by ReCorp. The flaw affects all versions up to and including 4.3.4, where authentication cookies stored in publicly accessible cookies.txt files can be read by unauthenticated attackers. It was published on December 13, 2025, and assigned a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). When a site administrator triggers a backup operation using an administrator-level user role, the plugin writes authentication cookies to a cookies.txt file that is stored in a publicly accessible web directory without access restrictions. An unauthenticated remote attacker can directly request this file over HTTP, obtaining valid session/authentication cookies without any credentials or user interaction. No authentication, special privileges, or complex conditions are required to exploit this flaw (Wordfence, ENISA EUVD).
Successful exploitation allows an unauthenticated attacker to obtain valid administrator authentication cookies, enabling complete account hijacking of the WordPress site's administrative account. This can lead to unauthorized modification of site content and settings, installation of malicious plugins or backdoors, exfiltration of sensitive user data, and full site compromise. The high scores across confidentiality, integrity, and availability reflect the potential for total loss of control over the affected WordPress installation (Wordfence, ENISA EUVD).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation (Wordfence). However, Nuclei detection templates for this CVE have been added to the ProjectDiscovery nuclei-templates repository, lowering the barrier for automated scanning (Nuclei Templates). The EPSS score is approximately 0.179%, indicating a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has published a detection (ID 530753) for this issue (Qualys).
cookies.txt file (e.g., GET /wp-content/plugins/export-wp-page-to-static-html/cookies.txt).cookies.txt file to extract valid WordPress authentication cookies (e.g., wordpress_logged_in_* or wordpress_sec_* cookies) belonging to an administrator account.curl --cookie) to authenticate as the administrator without knowing the password./wp-content/plugins/export-wp-page-to-static-html/cookies.txt or similar plugin subdirectories; automated scanning patterns (multiple sequential requests from a single IP targeting the cookies.txt path).cookies.txt files from unexpected or anonymous sources; repeated access from unfamiliar IP addresses to plugin directories.cookies.txt files in publicly accessible plugin directories containing WordPress authentication cookie values; unexpected new administrator accounts created in WordPress.Update the Export WP Page to Static HTML & PDF plugin to a version beyond 4.3.4, which contains the fix for this vulnerability (patch available via the WordPress plugin repository changeset) (WordPress Plugin Changeset). If an immediate update is not possible, deactivate the plugin temporarily and manually delete or restrict access to any cookies.txt files in the plugin directory using web server configuration (e.g., deny access via .htaccess or Nginx rules). Additionally, audit existing WordPress sessions, invalidate all active cookies by changing the WordPress security keys in wp-config.php, and review access logs for any prior unauthorized access to the exposed file (Wordfence).
Wordfence reported the vulnerability as part of their weekly WordPress vulnerability report for December 8–14, 2025, and it was included in CISA's vulnerability bulletin (SB25-349) (Wordfence Weekly Report, CISA Bulletin). The vulnerability received attention on social media platforms including Bluesky, and Nuclei detection templates were subsequently added to the ProjectDiscovery repository, indicating community interest in automated detection (Nuclei Templates). The high CVSS score of 9.8 drew attention despite the lack of active exploitation, with security aggregators such as VulDB, Vulners, and CVEFeed highlighting the issue.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."