Vulnerability
AnyWhere Elementor <= 1.2.7 – Freemius API Key Disclosure
Description
The plugin discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked.
CVE-ID
CVE-2023-0443
Vendor
WPVibes
Product
AnyWhere Elementor
Disclosure Timeline
Reported On: 18-01-23
Made Public On: 02-05-23
Fixed On: 19-01-23
Credits
Sanjay Das