The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
https://wpscan.com/vulnerability/4248a0af-1b7e-4e29-8129-3f40c1d0c560