CVE-2023-0443: AnyWhere Elementor < 1.2.8 - Freemius API Key Disclosure
The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0443?
The severity of CVE-2023-0443 is considered high due to the potential for unauthorized purchases using the Freemius Secret Key.
How do I fix CVE-2023-0443?
To fix CVE-2023-0443, you should update the AnyWhere Elementor WordPress plugin to version 1.2.8 or higher.
What type of vulnerability is CVE-2023-0443?
CVE-2023-0443 is a vulnerability that involves the disclosure of sensitive information, specifically a Freemius Secret Key.
Which versions of the AnyWhere Elementor plugin are affected by CVE-2023-0443?
CVE-2023-0443 affects AnyWhere Elementor WordPress plugin versions prior to 1.2.8.
What could an attacker do using the Freemius Secret Key disclosed in CVE-2023-0443?
An attacker could use the disclosed Freemius Secret Key to subscribe to the pro version of the plugin using fake payment methods without incurring any charges.