Skip to main content

Vendor/product archive

catchplugins / catch_themes_demo_import CVEs

Beta · best-effort

3 CVEs tagged to catchplugins / catch_themes_demo_import0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2022-0440

Published Mar 7, 2022

The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP fi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39352

Published Oct 21, 2021

The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions u…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24752

Published Oct 18, 2021

Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber…

CVSS 5.7 · Medium
Showing 1-3 of 3 CVEsPage 1 of 1