CVE-2025-11504
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-24

Last updated on: 2025-10-27

Assigner: Wordfence

Description
The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible for unauthenticated attackers to view the plugin's API key and subsequently use that to perform actions on the site like creating new posts and injecting XSS payloads.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-24
Last Modified
2025-10-27
Generated
2026-05-07
AI Q&A
2025-10-24
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
quickcreator ai_blog_writer 0.1.17
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

The Quickcreator – AI Blog Writer plugin for WordPress has a vulnerability in versions 0.0.9 to 0.1.17 where an unauthenticated attacker can access the /wp-content/plugins/quickcreator/dupasrala.txt file. This file exposes the plugin's API key, allowing the attacker to use it to perform actions on the site such as creating new posts and injecting cross-site scripting (XSS) payloads.


How can this vulnerability impact me? :

This vulnerability can impact you by allowing unauthenticated attackers to gain access to the plugin's API key, which they can then use to create unauthorized posts on your WordPress site and inject malicious scripts (XSS payloads). This can lead to defacement, spreading malware, or compromising site visitors' security.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart