PT-2025-7820 · WordPress · Enfold

Michael Mazzolini

+1

·

Published

2025-02-25

·

Updated

2025-02-28

·

CVE-2024-13693

CVSS v3.1
5.3
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

Enfold theme for WordPress versions up to, and including, 6.0.9

Description:

The issue allows unauthorized access to data due to a missing capability check in the avia-export-class.php file. This enables unauthenticated attackers to export all avia settings, potentially including sensitive information such as the `Mailchimp API Key`, `reCAPTCHA Secret Key`, or `Envato private token` if they are set.

Recommendations:

For Enfold theme for WordPress versions up to, and including, 6.0.9, update to a version higher than 6.0.9 to resolve the issue. As a temporary workaround, consider restricting access to the avia-export-class.php file to minimize the risk of exploitation.

Fix

Missing Authorization

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-13693

Affected Products

Enfold