Description
Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery.

This issue affects Export WP Page to Static HTML/CSS: from n/a through 6.0.0.
Published: 2026-05-25
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic CSRF flaw exposed by the Recorp Export WP Page to Static HTML/CSS plugin. An attacker could forge a request from a victim’s browser to invoke the plugin’s export functionality without the victim’s knowledge, potentially altering site content or generating unwanted static pages. The weakness is classified as CWE‑352 and is not exploitable for arbitrary code execution or direct data exfiltration, but it enables malicious state changes on the target site.

Affected Systems

This flaw affects the WordPress Export WP Page to Static HTML/CSS plugin (by Recorp) in all versions up to and including 6.0.0. Any WordPress installation that has this plugin installed and has users with permissions to invoke the export feature is vulnerable. Versions prior to the release of 6.0.1 contain the exploit.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity impact. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting the exploitation rate is not well documented. The attack likely requires a victim to be logged into WordPress and to visit a crafted URL, or for an attacker to host a malicious page that tricks the logged‑in user into sending a forged request. The vulnerability can be leveraged with minimal effort and no advanced prerequisites, so the risk remains moderate.

Generated by OpenCVE AI on May 25, 2026 at 22:22 UTC.

Remediation

Vendor Solution

Update the WordPress Export WP Page to Static HTML/CSS Plugin to the latest available version (at least 6.0.1).


OpenCVE Recommended Actions

  • Apply the official plugin update to version 6.0.1 or later.
  • Disable or restrict administrative access to the Export WP Page to Static HTML/CSS plugin if it is not essential for operations.
  • Enable WordPress’s built‑in non‑ce verification (nonces) on all plugin‑related requests to guarantee that only legitimate, user‑initiated actions are processed.

Generated by OpenCVE AI on May 25, 2026 at 22:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Myrecorp
Myrecorp export Wp Page To Static Html/css
Wordpress
Wordpress wordpress
Vendors & Products Myrecorp
Myrecorp export Wp Page To Static Html/css
Wordpress
Wordpress wordpress

Mon, 25 May 2026 21:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery. This issue affects Export WP Page to Static HTML/CSS: from n/a through 6.0.0.
Title WordPress Export WP Page to Static HTML/CSS plugin <= 6.0.0 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Subscriptions

Myrecorp Export Wp Page To Static Html/css
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-25T21:07:12.854Z

Reserved: 2026-01-23T12:32:02.838Z

Link: CVE-2026-24574

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T00:00:12Z

Weaknesses