CVE-2024-38749

MEDIUM

Olive Themes Olive One Click Demo Import <1.1.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Olive One Click Demo Import: from n/a through 1.1.2.

Scores

CVSS v3 5.3
EPSS 0.0039
EPSS Percentile 30.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
Olive Themes/Olive One Click Demo Import < 1.1.2
olivethemes/olive_one_click_demo_import < 1.1.2
Published Aug 13, 2024
Tracked Since Feb 18, 2026