5.3

CVE-2023-3779

Essential Addons For Elementor <=5.8.1 - Unauthenticated MailChimp API Key Disclosure

Essential Addons For Elementor <=5.8.1 - Unauthenticated MailChimp API Key Disclosure

The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp API key. We recommend resetting any MailChimp API keys if running a vulnerable version of this plugin with the MailChimp block enabled as the API key may have been compromised. This only affects sites running the premium version of the plugin and that have the Mailchimp block enabled on a page.
Mögliche Gegenmaßnahme
Essential Addons for Elementor – Popular Elementor Templates & Widgets: Update to version 5.8.2, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WpdeveloperEssential Addons For Elementor SwPlatformwordpress Version <= 5.8.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Essential Addons for Elementor – Popular Elementor Templates & Widgets
Version *-5.8.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.38
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2938177%40essential-addons-for-elementor-lite&new=2938177%40essential-addons-for-elementor-lite&sfp_email=&sfph_mail=
Patch
https://www.wordfence.com/threat-intel/vulnerabilities/id/e007c713-74bc-4ff5-a198-70dcc8a8ee68?source=cve
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/e007c713-74bc-4ff5-a198-70dcc8a8ee68
Third Party Advisory