Document Pro Elementor Information Exposure Vulnerability

Vulnerability

A vulnerability allowing information exposure has been identified in the Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress, affecting all versions through 1.0.9. The issue arises because the plugin improperly exposes sensitive Algolia API keys in the frontend JavaScript via wp_localize_script, without adequate access controls. This vulnerability allows unauthenticated attackers to access these API keys from the page source, potentially enabling unauthorized API calls to the associated Algolia search service.

Impact

Exposing sensitive information, specifically Algolia API keys, to unauthorized users. This could lead to unauthorized API calls to the victim's Algolia search service.

Added: Nov 11, 2025, 4:49 AM
Updated: Nov 11, 2025, 4:49 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
0.0
relevance
0.9
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.