Lucene search

K
wpvulndbSanjay DasWPVDB-ID:471F3226-8F90-43D1-B826-F11EF4BBD602
HistoryMay 02, 2023 - 12:00 a.m.

AnyWhere Elementor < 1.2.8 - Freemius API Key Disclosure

2023-05-0200:00:00
Sanjay Das
wpscan.com
7
plugin
secret key
unauthorized purchase
security
poc
disclosure

EPSS

0.001

Percentile

31.2%

The plugin discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked.

PoC

See the disclosed secret key in includes/pro.php.

EPSS

0.001

Percentile

31.2%

Related for WPVDB-ID:471F3226-8F90-43D1-B826-F11EF4BBD602