Olive One Click Demo Import [olive-one-click-demo-import] <= 1.1.2 (unfixed + closed)
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Olive One Click Demo Import: from n/a through 1.1.2.
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 13, 2024
CVE-2024-38749 on NVD →
Olive One Click Demo Import <= 1.1.2 - Unauthenticated Information Exposure
medium
The Olive One Click Demo Import plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to extract potentially sensitive information.
- CVSS:
- 5.3
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
- Disclosed:
- Jul 11, 2024
CVE-2024-38749 on NVD →
Olive One Click Demo Import [olive-one-click-demo-import] < 1.1.2 (closed)
unknown
[en] Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- Jun 9, 2024
CVE-2024-32715 on NVD →
Olive One Click Demo Import <= 1.1.1 - Missing Authorization
medium
The Olive One Click Demo Import plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capability checking on several rest routes in versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to perform unauthorized actions. CVE-2024-32715 appears t...
- CVSS:
- 6.5
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.2
- Disclosed:
- Mar 20, 2024
CVE-2024-2702 on NVD →
Olive One Click Demo Import [olive-one-click-demo-import] < 1.1.2 (closed)
unknown
[en] Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- Mar 20, 2024
CVE-2024-2702 on NVD →
Olive One Click Demo Import [olive-one-click-demo-import] <= 1.1.2 (unfixed + closed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 20, 2023
CVE-2023-29102 on NVD →
Olive One Click Demo Import <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Upload in olive_one_click_demo_import_save_file
high
The Olive One Click Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the olive_one_click_demo_import_save_file function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with administrator-level privileges and abov...
- CVSS:
- 7.2
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 28, 2023
CVE-2023-29102 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database