Sensitive Information Exposure in Export WP Page to Static HTML & PDF Plugin for WordPress
CVE-2025-11693

9.8CRITICAL

What is CVE-2025-11693?

The Export WP Page to Static HTML & PDF plugin for WordPress is susceptible to sensitive information exposure, risking the compromise of authentication cookies. All versions prior to and including 4.3.4 are affected. This vulnerability arises when an unauthenticated attacker gains access to cookies.txt files that may record sensitive authentication information, particularly if a site administrator has used a specific role to trigger a backup. As a result, attackers can exploit this issue by retrieving confidential cookie data from publicly accessible files, leading to potential unauthorized access and further security breaches.

Affected Version(s)

Export WP Pages to HTML & PDF – Simply Create a Static Website * <= 4.3.4

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.
CVE-2025-11693 : Sensitive Information Exposure in Export WP Page to Static HTML & PDF Plugin for WordPress