The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 28 Feb 2025 02:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Kriesi
Kriesi enfold |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:kriesi:enfold:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Kriesi
Kriesi enfold |
Tue, 25 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 25 Feb 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set. | |
Title | Enfold <= 6.0.9 - Missing Authorization to Sensitive Information Disclosure in avia-export-class.php | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-25T14:37:21.976Z
Reserved: 2025-01-23T20:46:48.682Z
Link: CVE-2024-13693

Updated: 2025-02-25T14:32:31.148Z

Status : Analyzed
Published: 2025-02-25T10:15:09.643
Modified: 2025-02-28T01:30:32.830
Link: CVE-2024-13693

No data.

No data.