Catch Themes Demo Import Missing Authorization Vulnerability Allowing Unauthorized Plugin Installation

Vulnerability

A vulnerability exists in the Catch Themes Demo Import plugin for WordPress, specifically in versions through 3.3. The issue is a missing authorization that allows authenticated users with subscriber-level access and above to exploit the 'activate_plugin' GET parameter. This vulnerability enables the unauthorized installation of a hardcoded plugin, 'essential-content-types', from the WordPress Plugin Repository.

Impact

Exploitation of this vulnerability allows for unauthorized installation of plugins, which could lead to further vulnerabilities or issues, depending on the installed plugin's functionality.

Reproduction

To reproduce this vulnerability, an authenticated user with subscriber-level access can send a request to the WordPress admin area with the 'activate_plugin' GET parameter set to 'essential-content-types'. This will trigger the 'catch_themes_demo_import_activate_plugin' function, which installs the specified plugin without proper authorization checks.

Remediation

Users are advised to update the Catch Themes Demo Import plugin to version 3.4 or later, where this vulnerability has been patched.

Added: Jul 16, 2026, 4:24 AM
Updated: Jul 16, 2026, 4:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.3
remediation
0.0
relevance
9.8
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.