Document Pro Elementor Information Exposure Vulnerability
Vulnerability
A vulnerability allowing information exposure has been identified in the Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress, affecting all versions through 1.0.9. The issue arises because the plugin improperly exposes sensitive Algolia API keys in the frontend JavaScript via wp_localize_script, without adequate access controls. This vulnerability allows unauthenticated attackers to access these API keys from the page source, potentially enabling unauthorized API calls to the associated Algolia search service.
Impact
Exposing sensitive information, specifically Algolia API keys, to unauthorized users. This could lead to unauthorized API calls to the victim's Algolia search service.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
