CVE · Medium

CVE-2023-3709 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.71

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-3709 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.71 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 1.3.71 1.3.71 2023-07-17

CVE-2023-3709

The Royal Elementor Addons plugin through version 1.3.70 exposes MailChimp API keys in page source code whenever the MailChimp block is active, allowing any unauthenticated user to view and retrieve sensitive credentials. An attacker without authentication can examine the page's HTML to obtain a valid MailChimp API key. Users running affected versions with the MailChimp block enabled should reset their MailChimp API keys immediately, as they may have been exposed. The vulnerability is resolved in version 1.3.71 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.