CVE-2025-11504
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-24

Last updated on: 2025-10-27

Assigner: Wordfence

Description
The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible for unauthenticated attackers to view the plugin's API key and subsequently use that to perform actions on the site like creating new posts and injecting XSS payloads.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-24
Last Modified
2025-10-27
Generated
2026-06-16
AI Q&A
2025-10-24
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
quickcreator ai_blog_writer 0.1.17
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The Quickcreator – AI Blog Writer plugin for WordPress has a vulnerability in versions 0.0.9 to 0.1.17 where an unauthenticated attacker can access the /wp-content/plugins/quickcreator/dupasrala.txt file. This file exposes the plugin's API key, allowing the attacker to use it to perform actions on the site such as creating new posts and injecting cross-site scripting (XSS) payloads.

Impact Analysis

This vulnerability can impact you by allowing unauthenticated attackers to gain access to the plugin's API key, which they can then use to create unauthorized posts on your WordPress site and inject malicious scripts (XSS payloads). This can lead to defacement, spreading malware, or compromising site visitors' security.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-11504. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart