The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set.
References
Configurations
History
28 Feb 2025, 01:30
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:kriesi:enfold:*:*:*:*:*:wordpress:*:* | |
First Time |
Kriesi enfold
Kriesi |
|
CWE | CWE-862 | |
Summary |
|
|
References | () https://themeforest.net/item/enfold-responsive-multipurpose-theme/4519990#item-description__changelog - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/61a9ad18-28d4-488c-b3a7-e35745f9c83e?source=cve - Third Party Advisory |
25 Feb 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-25 10:15
Updated : 2025-02-28 01:30
NVD link : CVE-2024-13693
Mitre link : CVE-2024-13693
CVE.ORG link : CVE-2024-13693
JSON object : View
Products Affected
kriesi
- enfold