The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Feb 2025 02:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Kriesi
Kriesi enfold |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:kriesi:enfold:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Kriesi
Kriesi enfold |
Tue, 25 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 25 Feb 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set. | |
Title | Enfold <= 6.0.9 - Missing Authorization to Sensitive Information Disclosure in avia-export-class.php | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-02-25T09:21:33.130Z
Updated: 2025-02-25T14:37:21.976Z
Reserved: 2025-01-23T20:46:48.682Z
Link: CVE-2024-13693

Updated: 2025-02-25T14:32:31.148Z

Status : Analyzed
Published: 2025-02-25T10:15:09.643
Modified: 2025-02-28T01:30:32.830
Link: CVE-2024-13693

No data.