---
id: CVE-2025-11504
title: >-
  The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to
  Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the
  /wp-content/plugins/quickcreator/dupasrala.txt file
summary: >-
  The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to
  Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the
  /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible
  for unauthenticate…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-532
published: '2025-10-24'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11504'
references:
  - url: 'https://wordpress.org/plugins/quickcreator/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/561f171e-f13e-408b-a63e-bf6a512d4463?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00333
epssPercentile: 0.24485
ingestedAt: '2026-10-08T11:31:27.569Z'
---

## Overview

The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible for unauthenticated attackers to view the plugin's API key and subsequently use that to perform actions on the site like creating new posts and injecting XSS payloads.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
