Enfold WordPress Theme Missing Capability Check Vulnerability in avia-export-class.php

Vulnerability

A vulnerability exists in the Enfold theme for WordPress, in all versions through 6.0.9, due to a missing capability check in the avia-export-class.php file. This flaw allows unauthorized access to sensitive data, enabling unauthenticated attackers to export all Avia settings. The exported data may contain confidential information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token, if these are configured.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information, including API keys and private tokens.

Remediation

Users are advised to update the Enfold theme to version 7.0 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
2.5
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.