Quickcreator – AI Blog Writer 0.0.9 - 0.1.17 - Unauthenticated API Key Exposure
highThe Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible for unauthenticated attackers to view the plugin's API key and subsequently use that to perform actio...
- CVSS:
- 7.5
- Affected:
- 0.0.9 – 0.1.17
- Fixed in:
- 0.1.18
- Disclosed:
- Oct 23, 2025