CVE 9.8 CRITICAL

Export WP Page to Static HTML & PDF <= 4.3.4 - Unauthenticated Cookie Exposure via Log File_CVE-2025-11693

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.4 through publicly exposed cookies.txt files containing authentication cookies. This makes it possible for unauthenticated attackers to cookies that may have been injected into the log file if the site administrator triggered a back-up using a specific user role like 'administrator.'

Basic Information

ID CVE-2025-11693
Source Wordfence
Published Dec 13, 2025 at 04:31

Affected Product

Vendor recorp
Product Export WP Pages to HTML & PDF – Simply Create a Static Website
Version *
Affected Versions recorp Export WP Pages to HTML & PDF – Simply Create a Static Website *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.