Catch Themes Demo Import
- <= 3.3
A vulnerability exists in the Catch Themes Demo Import plugin for WordPress, specifically in versions through 3.3. The issue is a missing authorization that allows authenticated users with subscriber-level access and above to exploit the 'activate_plugin' GET parameter. This vulnerability enables the unauthorized installation of a hardcoded plugin, 'essential-content-types', from the WordPress Plugin Repository.
Exploitation of this vulnerability allows for unauthorized installation of plugins, which could lead to further vulnerabilities or issues, depending on the installed plugin's functionality.
To reproduce this vulnerability, an authenticated user with subscriber-level access can send a request to the WordPress admin area with the 'activate_plugin' GET parameter set to 'essential-content-types'. This will trigger the 'catch_themes_demo_import_activate_plugin' function, which installs the specified plugin without proper authorization checks.
Users are advised to update the Catch Themes Demo Import plugin to version 3.4 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.