Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter
medium
The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activate_plugin GET parameter is present, calling Plugin_Upgrader::install() to download a...
- CVSS:
- 4.3
- Affected:
- up to 3.3
- Fixed in:
- 3.4
- Disclosed:
- Jul 15, 2026
CVE-2026-15336 on NVD →
Catch Themes Demo Import [catch-themes-demo-import] < 2.1.1
unknown
[en] The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants s...
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- Mar 7, 2022
CVE-2022-0440 on NVD →
Catch Themes Demo Import <= 2.1 - Authenticated (Admin+) Arbitrary File Upload
high
The Catch Themes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.1. This is due to insufficient file type validation on imported files that makes it possible for high-level authenticated users, such as administrators, to upload arbitrary files onto a vulnerab...
- CVSS:
- 7.2
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- Feb 7, 2022
CVE-2022-0440 on NVD →
Catch Themes Demo Import <= 1.7 - Arbitrary File Upload
high
The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to up...
- CVSS:
- 7.2
- Affected:
- up to 1.7
- Fixed in:
- 1.8
- Disclosed:
- Oct 21, 2021
CVE-2021-39352 on NVD →
Catch Themes Demo Import [catch-themes-demo-import] < 1.8
unknown
[en] The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges...
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- Oct 21, 2021
CVE-2021-39352 on NVD →
Catch Themes Demo Import [catch-themes-demo-import] < 1.6
unknown
[en] Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin be...
- Affected:
- up to 1.6
- Fixed in:
- 1.6
- Disclosed:
- Oct 18, 2021
CVE-2021-24752 on NVD →
CatchThemes Plugins (Various Versions) - Missing Authorization
medium
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before...
- CVSS:
- 5.4
- Affected:
- up to 1.6
- Fixed in:
- 1.6
- Disclosed:
- Sep 20, 2021
CVE-2021-24752 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database