Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53873 | The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 28 Feb 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kriesi
Kriesi enfold |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:kriesi:enfold:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Kriesi
Kriesi enfold |
Tue, 25 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Feb 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set. | |
| Title | Enfold <= 6.0.9 - Missing Authorization to Sensitive Information Disclosure in avia-export-class.php | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-25T14:37:21.976Z
Reserved: 2025-01-23T20:46:48.682Z
Link: CVE-2024-13693
Updated: 2025-02-25T14:32:31.148Z
Status : Analyzed
Published: 2025-02-25T10:15:09.643
Modified: 2025-02-28T01:30:32.830
Link: CVE-2024-13693
No data.
OpenCVE Enrichment
No data.
EUVD