CVE-2025-11504
BaseFortify
Publication date: 2025-10-24
Last updated on: 2025-10-27
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| quickcreator | ai_blog_writer | 0.1.17 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-532 | The product writes sensitive information to a log file. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The Quickcreator β AI Blog Writer plugin for WordPress has a vulnerability in versions 0.0.9 to 0.1.17 where an unauthenticated attacker can access the /wp-content/plugins/quickcreator/dupasrala.txt file. This file exposes the plugin's API key, allowing the attacker to use it to perform actions on the site such as creating new posts and injecting cross-site scripting (XSS) payloads.
How can this vulnerability impact me? :
This vulnerability can impact you by allowing unauthenticated attackers to gain access to the plugin's API key, which they can then use to create unauthorized posts on your WordPress site and inject malicious scripts (XSS payloads). This can lead to defacement, spreading malware, or compromising site visitors' security.