External risk intelligence

WordPress Plugin Exposes Authentication Cookies via Exposed Files.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-11693

The vulnerability exists in a WordPress plugin. WordPress sites are commonly deployed as public-facing web applications. Because the plugin functionality involves generating files (HTML/PDF) that may be stored in web-accessible directories, the resulting cookies.txt file is likely to be reachable via a public URL if the server is not specifically configured to restrict access to these files.

Information Disclosure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This situation involves a WordPress plugin that could expose sensitive authentication information through publicly accessible files. While the impact hinges on specific administrative actions and site configurations, the potential for unauthorized access to user credentials warrants attention to confirm if your environment is affected.

  • Plugin may expose user login details.
  • Directs attention to potential unauthorized access risks.
  • Verify plugin usage and review access controls.

Attack Path

How an attacker could exploit the issue

An attacker could gain access to sensitive authentication cookies by exploiting a flaw in a WordPress plugin that creates static HTML and PDF versions of pages. If a site administrator uses a specific user role to trigger a backup, the plugin might expose a file containing these cookies through publicly accessible links. This could allow an unauthenticated attacker to potentially gain unauthorized access to user sessions and site data.

  • Publicly accessible cookie file.
  • Plugin backup function triggers exposure.
  • Risk of unauthorized access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could expose authentication cookies stored in publicly accessible `cookies.txt` files. If a site administrator with an 'administrator' user role triggers a backup, these cookies might be written to the log file and then become available to unauthenticated attackers.

  • Authentication cookies are at risk.
  • Attackers may access exposed cookie files.
  • Unauthorized access to user accounts could occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

WordPress site owners and their development teams should prioritize addressing this vulnerability by first identifying all instances of the affected plugin, confirming its exposure to the public internet, and then assessing its business criticality. This initial triage will enable a risk-based approach to planning remediation, which may involve coordinating with vendors or implementing temporary mitigations.

  • WordPress site owners should own the issue.
  • Verify plugin presence and internet reachability.
  • Plan remediation based on business impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Export WP Page to Static HTML & PDF plugin?

This WordPress plugin allows site administrators to convert web pages into static HTML files or PDF documents. It is typically used for archival purposes, site migration, or creating offline versions of content. By automating the export process, the plugin generates file-based copies of site data, which can occasionally include auxiliary files created during site maintenance.

What does CWE-200 mean for CVE-2025-11693?

CWE-200 refers to Information Exposure. In the context of this CVE, it means the plugin inadvertently makes sensitive data—specifically authentication cookies—available to unauthorized parties. Because these cookies act as digital keys to a user's session, their exposure allows an attacker to potentially impersonate legitimate users without needing a password.

How do attackers access these cookies?

An attacker can retrieve the sensitive data if a site administrator uses the plugin to perform a backup while logged in with specific roles, such as 'administrator.' This process writes authentication cookies to a 'cookies.txt' file that is stored in a publicly accessible directory. The bug is not triggered by normal visitor traffic; it relies on the accidental creation and exposure of this file by an administrator.

Do I need to worry if my site is not internet-facing?

Halo Surface Signal indicates that while WordPress sites are often public, the core risk is the file's accessibility. If your site is strictly internal, the reach of an attacker is limited to those with network access. However, because the plugin creates files in web-accessible directories by default, even private sites might be at risk if the server configuration does not explicitly block unauthorized web requests to those directories.

How should I respond to this vulnerability?

Start by identifying if the 'Export WP Page to Static HTML & PDF' plugin is installed on your WordPress instances. Check the plugin's file directory to see if any 'cookies.txt' files have been generated. If the plugin is not essential, consider removing it. If you must use it, ensure your server is configured to restrict public access to sensitive log or data directories created by the plugin.

References