Information disclosure in Royal Elementor Addons - CVE-2023-3709
Published: July 20, 2023
Vulnerability identifier: #VU78452
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-3709
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: WP Royal
Affected software:
Royal Elementor Addons
Royal Elementor Addons
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected plugin adds the API key to the source code of any page running the MailChimp block. A remote attacker can obtain a site's MailChimp API key.
How to mitigate CVE-2023-3709
Install updates from vendor's website.