AnyWhere Elementor < 1.2.8 – Freemius API Key Disclosure
Discription
The plugin discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked.
### PoC
See the disclosed secret key in `includes/pro.php`.Read More
References
Back to Main