Web / CMS

Information Disclosure

AnyWhere Elementor <= 1.2.7 - Freemius API Key Disclosure

AnyWhere Elementor <= 1.2.7 – Freemius API Key Disclosure The plugin discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers

5.3
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS68
PUBLISHED
2023-06-19
CVE IDs
CVE-2023-0443
VENDORS
WPVibes
PUBLIC EXPLOIT
PoC public
CWE
CWE-200
PRODUCT
AnyWhere Elementor (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

AnyWhere Elementor <= 1.2.7 – Freemius API Key Disclosure

The plugin discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked.

Vulnerability details

Vulnerability details

CVE-2023-0443
CWE-200
Medium | 5.3

AnyWhere Elementor <= 1.2.7 – Freemius API Key Disclosure The plugin discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount.

Auth:
None (remote)
Impact:
Limited data disclosure
DISCLOSURE

Disclosure timeline

2023-01-18 Reported On

2023-05-02 Made Public On

2023-01-19 Fixed On

Credits

Sanjay Das