Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High2
Medium2
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2026-07-17

CVE-2026-15336 - Catch Themes Demo Import Plugin

The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activate_plugin GET parameter is present, calling Plugin_Upgrader::install() to download and install a plugin from WordPress.org before performing the current_user_can('activate_plugins') capability check. This makes it possible for authenticated attackers, with subscriber-level access and above, to install the hardcoded 'essential-content-types' plugin from the WordPress.

PLUGIN Catch Themes Demo Import

CVE-2026-15336

MEDIUM CVSS 4.3 2026-07-16
Threat Entry Updated 2024-11-21

CVE-2022-0440 - Catch Themes Demo Import Plugin

The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set to true)

PLUGIN Catch Themes Demo Import

CVE-2022-0440

HIGH CVSS 7.2 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-39352 - Catch Themes Demo Import Plugin

The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to upload malicious files that can be used to achieve remote code execution.

PLUGIN Catch Themes Demo Import

CVE-2021-39352

HIGH CVSS 7.2 2021-10-21
Threat Entry Updated 2024-11-21

CVE-2021-24752 - Catch Themes Demo Import Plugin

Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before 1.5, Generate Child Theme WordPress plugin before 1.6, Essential Content Types WordPress plugin before 1.9, Catch Web Tools WordPress plugin before 2.7, Catch Under Construction WordPress plugin before 1.4, Catch Themes Demo Import WordPress plugin before 1.6, Catch Sticky Menu WordPress plugin before…

PLUGIN Catch Themes Demo Import

CVE-2021-24752

MEDIUM CVSS 5.7 2021-10-18
Scroll to top