Information disclosure in Royal Elementor Addons - CVE-2023-3709

 

Information disclosure in Royal Elementor Addons - CVE-2023-3709

Published: July 20, 2023


Vulnerability identifier: #VU78452
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-3709
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: WP Royal
Affected software:
Royal Elementor Addons

Detailed vulnerability description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected plugin adds the API key to the source code of any page running the MailChimp block. A remote attacker can obtain a site's MailChimp API key.


How to mitigate CVE-2023-3709

Install updates from vendor's website.

Sources