plugin

Olive One Click Demo Import Vulnerabilities

7 known security issues reported for the Olive One Click Demo Import WordPress plugin. Most recent disclosed Aug 13, 2024.

1 high 2 medium

Running Olive One Click Demo Import on your site? Check whether your installed version is affected.

Scan your site free

Olive One Click Demo Import [olive-one-click-demo-import] <= 1.1.2 (unfixed + closed)

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Olive One Click Demo Import: from n/a through 1.1.2.

Affected:
up to 1.1.2
Fix:
No patched version reported
Disclosed:
Aug 13, 2024

CVE-2024-38749 on NVD →

Olive One Click Demo Import <= 1.1.2 - Unauthenticated Information Exposure

medium

The Olive One Click Demo Import plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to extract potentially sensitive information.

CVSS:
5.3
Affected:
up to 1.1.2
Fix:
No patched version reported
Disclosed:
Jul 11, 2024

CVE-2024-38749 on NVD →

Olive One Click Demo Import [olive-one-click-demo-import] < 1.1.2 (closed)

unknown

[en] Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
Jun 9, 2024

CVE-2024-32715 on NVD →

Olive One Click Demo Import <= 1.1.1 - Missing Authorization

medium

The Olive One Click Demo Import plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capability checking on several rest routes in versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to perform unauthorized actions. CVE-2024-32715 appears t...

CVSS:
6.5
Affected:
up to 1.1.1
Fixed in:
1.1.2
Disclosed:
Mar 20, 2024

CVE-2024-2702 on NVD →

Olive One Click Demo Import [olive-one-click-demo-import] < 1.1.2 (closed)

unknown

[en] Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
Mar 20, 2024

CVE-2024-2702 on NVD →

Olive One Click Demo Import [olive-one-click-demo-import] <= 1.1.2 (unfixed + closed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.

Affected:
up to 1.1.2
Fix:
No patched version reported
Disclosed:
Dec 20, 2023

CVE-2023-29102 on NVD →

Olive One Click Demo Import <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Upload in olive_one_click_demo_import_save_file

high

The Olive One Click Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the olive_one_click_demo_import_save_file function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with administrator-level privileges and abov...

CVSS:
7.2
Affected:
up to 1.1.2
Fix:
No patched version reported
Disclosed:
Aug 28, 2023

CVE-2023-29102 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database