Access violation vulnerability in Enfold – Responsive Multi-Purpose Theme 6.0.9

The Enfold theme for WordPress has a security issue that could allow unauthorized users to access private information. This is because a capability check is missing in the avia-export-class.php file in all versions up to 6.0.9. This means that attackers without proper authentication could export all avia settings, including sensitive information like Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set.

Detected in:

Enfold - Responsive Multi-Purpose Theme fixed vulnerable versions: >= * <= 6.0.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.