CVE Database /
CVE-2023-3709
CVE · Medium
CVE-2023-3709 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.71
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-3709
|
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.71 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
5.3
|
< 1.3.71
|
1.3.71 |
2023-07-17 |
—
|
CVE-2023-3709
The Royal Elementor Addons plugin through version 1.3.70 exposes MailChimp API keys in page source code whenever the MailChimp block is active, allowing any unauthenticated user to view and retrieve sensitive credentials. An attacker without authentication can examine the page's HTML to obtain a valid MailChimp API key. Users running affected versions with the MailChimp block enabled should reset their MailChimp API keys immediately, as they may have been exposed. The vulnerability is resolved in version 1.3.71 and later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings