The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-53873 | The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set. | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Fri, 28 Feb 2025 02:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Kriesi
         Kriesi enfold  | 
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:kriesi:enfold:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | 
        
        Kriesi
         Kriesi enfold  | 
Tue, 25 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 25 Feb 2025 09:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set. | |
| Title | Enfold <= 6.0.9 - Missing Authorization to Sensitive Information Disclosure in avia-export-class.php | |
| Weaknesses | CWE-284 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-25T14:37:21.976Z
Reserved: 2025-01-23T20:46:48.682Z
Link: CVE-2024-13693
Updated: 2025-02-25T14:32:31.148Z
Status : Analyzed
Published: 2025-02-25T10:15:09.643
Modified: 2025-02-28T01:30:32.830
Link: CVE-2024-13693
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD