Olivethemes develops the Olive One Click Demo Import plugin, a WordPress tool for populating demonstration content and configurations, with a vulnerability profile centered on authorization and data-handling issues. The recurring weakness classes—missing authorization checks, exposure of sensitive information, and unrestricted file uploads—reflect common risks in WordPress plugin functionality where administrative and user-input boundaries require careful enforcement. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Olivethemes over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2702CRITICAL Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Dem | Mar 20, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-38749HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality Not Properly Constrained by ACLs | Aug 13, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-32715HIGH Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. | Jun 9, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-29102HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. | Dec 20, 2023 | 7.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Olivethemes.
Media articles that mention a CVE ID that affects a product developed by Olivethemes — matched by CVE ID, not by vendor name.