Impact
The Export WP Page to Static HTML & PDF plugin allows unauthenticated users to download a publicly accessible cookies.txt file that may contain authentication cookies that were injected during an administrator‑triggered backup. This exposure results in the disclosure of authentication credentials and is classified as a sensitive information exposure (CWE‑200).
Affected Systems
The affected product is ReCorp’s Export WordPress Pages to Static HTML & PDF plugin, version 4.3.4 and all earlier releases. No other vendor or product is explicitly listed.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, while the EPSS score of 5% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit this weakness simply by requesting the publicly accessible cookies.txt file, which exposes authentication cookies.
OpenCVE Enrichment