S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Apr 23, 2026

CVE-2025-11693 Scanner

CVE-2025-11693 Scanner - Information Disclosure vulnerability in Export WP Page to Static HTML

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.9k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-11693
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.4 through publicly exposed cookies.txt files containing authentication cookies. This makes it possible for unauthenticated attackers to cookies that may have been injected into the log file if the site administrator triggered a back-up using a specific user role like 'administrator.'

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Export WordPress Pages to Static HTML & PDF — Static Site Exportby recorp
0
Updated Sep 9, 2026View on NVD →
Detail

The Export WP Page to Static HTML plugin is widely used by WordPress site administrators to convert WordPress pages and posts into static HTML or PDF files. This conversion aids in reducing server load and improving page load times. Deployed by web administrators and hosted service providers, the plugin is particularly beneficial for sites requiring fast static content delivery. However, the plugin's operation, especially in older versions, may inadvertently expose sensitive data. Awareness and timely updates are critical to maintain website integrity when using the plugin. Emphasizing security through regular updates is paramount for any site utilizing this tool.

This vulnerability involves the exposure of sensitive information through publicly accessible cookies.txt files. Exploitation of this issue allows unauthenticated attackers to retrieve authentication cookies, increasing the risk of unauthorized access. Such scenarios enable attackers to potentially impersonate legitimate users if they compromise cookie data. Public access to authentication information significantly heightens the risk of account takeovers. Therefore, addressing this vulnerability promptly is crucial. Regular monitoring and updates help mitigate these risks effectively.

The core technical issue stems from exposed cookies.txt files that store authentication data. This vulnerability can occur when specific conditions, such as backups triggered by site administrators with particular roles, are met. Once the conditions are fulfilled, any unauthenticated user could access sensitive authentication cookies, posing a significant security risk. Past incidents have shown that inadvertent file access often occurs through predictable URL exposure. Addressing such configurations prevents unauthorized data visibility and ensures site security.

The potential effects of exploiting this vulnerability include unauthorized access and account compromise. Attackers intercepting the cookies can impersonate users, gaining access to their accounts without further authentication. Such breaches may lead to data modification, service disruptions, or administrative control loss. Maintaining updated versions of the plugin helps mitigate such threats. To safeguard against these, maintaining rigorous access controls and regular updating practices is advised.

REFERENCES

Solution Advice
  • Update the Export WP Page to Static HTML plugin to the latest version beyond 4.3.4.
  • Regularly check for and apply security patches and updates from the plugin's developers.
  • Restrict access to sensitive files and directories within the website's server configuration.
  • Implement a more secure process for handling and storing authentication cookies and authentication-related data.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-11693 Scanner - Information Disclosure vulnerability in Export WP Page to Static HTML | S4E