Enfold
cpe:2.3:a:kriesi:enfold:*:*:*:*:wordpress:*:*
- <= 6.0.9
A vulnerability exists in the Enfold theme for WordPress, in all versions through 6.0.9, due to a missing capability check in the avia-export-class.php file. This flaw allows unauthorized access to sensitive data, enabling unauthenticated attackers to export all Avia settings. The exported data may contain confidential information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token, if these are configured.
Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information, including API keys and private tokens.
Users are advised to update the Enfold theme to version 7.0 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.