First published: Tue Aug 13 2024(Updated: )
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Olive One Click Demo Import: from n/a through 1.1.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Olive One Click Demo Import | <=1.1.2 | |
WordPress One Click Demo Import | <=1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38749 is classified as a high severity vulnerability due to the exposure of sensitive information.
To fix CVE-2024-38749, update the Olive One Click Demo Import plugin to version 1.1.3 or later.
CVE-2024-38749 specifically involves the exposure of sensitive information due to improper access control mechanisms.
CVE-2024-38749 affects Olive One Click Demo Import versions up to and including 1.1.2.
CVE-2024-38749 can lead to unauthorized access to sensitive information that should be protected by access control lists.