PT-2023-16274 · WordPress · Anywhere Elementor
P3N7A90N
+1
·
Published
2023-05-30
·
Updated
2025-01-10
·
CVE-2023-0443
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AnyWhere Elementor WordPress plugin versions prior to 1.2.8
Description
The issue allows an attacker to obtain a Freemius Secret Key, which could be used to purchase the pro subscription using test credit card numbers without actually paying the amount. The key in question has been revoked.
Recommendations
For versions prior to 1.2.8, update to version 1.2.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's subscription functionality until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anywhere Elementor