CVE-2025-11693
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-11693 is a Sensitive Information Exposure vulnerability in the Export WP Page to Static HTML & PDF plugin for WordPress (also known as "Export WP Pages to HTML & PDF – Simply Create a Static Website"), developed by ReCorp. The flaw affects all versions up to and including 4.3.4, where authentication cookies stored in publicly accessible cookies.txt files can be read by unauthenticated attackers. It was published on December 13, 2025, and assigned a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). When a site administrator triggers a backup operation using an administrator-level user role, the plugin writes authentication cookies to a cookies.txt file that is stored in a publicly accessible web directory without access restrictions. An unauthenticated remote attacker can directly request this file over HTTP, obtaining valid session/authentication cookies without any credentials or user interaction. No authentication, special privileges, or complex conditions are required to exploit this flaw (Wordfence, ENISA EUVD).

Impact

Successful exploitation allows an unauthenticated attacker to obtain valid administrator authentication cookies, enabling complete account hijacking of the WordPress site's administrative account. This can lead to unauthorized modification of site content and settings, installation of malicious plugins or backdoors, exfiltration of sensitive user data, and full site compromise. The high scores across confidentiality, integrity, and availability reflect the potential for total loss of control over the affected WordPress installation (Wordfence, ENISA EUVD).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation (Wordfence). However, Nuclei detection templates for this CVE have been added to the ProjectDiscovery nuclei-templates repository, lowering the barrier for automated scanning (Nuclei Templates). The EPSS score is approximately 0.179%, indicating a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has published a detection (ID 530753) for this issue (Qualys).

Exploitation steps

  1. Reconnaissance: Use tools like Shodan, Censys, or WPScan to identify WordPress sites running the "Export WP Page to Static HTML & PDF" plugin version ≤ 4.3.4.
  2. Locate the exposed file: Send an unauthenticated HTTP GET request to the target site's web root or plugin directory to locate the publicly accessible cookies.txt file (e.g., GET /wp-content/plugins/export-wp-page-to-static-html/cookies.txt).
  3. Extract authentication cookies: Parse the retrieved cookies.txt file to extract valid WordPress authentication cookies (e.g., wordpress_logged_in_* or wordpress_sec_* cookies) belonging to an administrator account.
  4. Session hijacking: Inject the extracted cookies into a browser or HTTP client (e.g., using browser developer tools or a tool like curl --cookie) to authenticate as the administrator without knowing the password.
  5. Achieve full site control: With administrator access, install malicious plugins, create backdoor accounts, exfiltrate user data, or deface the site (Wordfence, Nuclei Templates).

Indicators of compromise

  • Network: Unauthenticated HTTP GET requests to paths such as /wp-content/plugins/export-wp-page-to-static-html/cookies.txt or similar plugin subdirectories; automated scanning patterns (multiple sequential requests from a single IP targeting the cookies.txt path).
  • Logs: Web server access logs (Apache/Nginx) showing 200 OK responses to requests for cookies.txt files from unexpected or anonymous sources; repeated access from unfamiliar IP addresses to plugin directories.
  • File System: Presence of cookies.txt files in publicly accessible plugin directories containing WordPress authentication cookie values; unexpected new administrator accounts created in WordPress.
  • WordPress Activity: Unexpected admin logins from unfamiliar IP addresses or geographic locations; new plugin installations or theme changes not initiated by known administrators; changes to WordPress user roles or passwords.

Mitigation and workarounds

Update the Export WP Page to Static HTML & PDF plugin to a version beyond 4.3.4, which contains the fix for this vulnerability (patch available via the WordPress plugin repository changeset) (WordPress Plugin Changeset). If an immediate update is not possible, deactivate the plugin temporarily and manually delete or restrict access to any cookies.txt files in the plugin directory using web server configuration (e.g., deny access via .htaccess or Nginx rules). Additionally, audit existing WordPress sessions, invalidate all active cookies by changing the WordPress security keys in wp-config.php, and review access logs for any prior unauthorized access to the exposed file (Wordfence).

Community reactions

Wordfence reported the vulnerability as part of their weekly WordPress vulnerability report for December 8–14, 2025, and it was included in CISA's vulnerability bulletin (SB25-349) (Wordfence Weekly Report, CISA Bulletin). The vulnerability received attention on social media platforms including Bluesky, and Nuclei detection templates were subsequently added to the ProjectDiscovery repository, indicating community interest in automated detection (Nuclei Templates). The high CVSS score of 9.8 drew attention despite the lack of active exploitation, with security aggregators such as VulDB, Vulners, and CVEFeed highlighting the issue.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16145HIGH7.2
  • gdpr-compliant-recaptcha-for-all-forms
NoYesAug 15, 2026
CVE-2026-18387MEDIUM6.5
  • groundhogg
NoYesAug 15, 2026
CVE-2026-16586MEDIUM6.5
  • contest-gallery
NoYesAug 15, 2026
CVE-2026-17090MEDIUM6.4
  • beaver-builder-lite-version
NoYesAug 15, 2026
CVE-2026-16146MEDIUM4.9
  • gdpr-compliant-recaptcha-for-all-forms
NoYesAug 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management