PT-2021-16253 · Catch Themes · Catch Gallery+12
Apple502J
·
Published
2021-10-18
·
Updated
2022-10-25
·
CVE-2021-24752
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Essential Widgets WordPress plugin versions prior to 1.9
To Top WordPress plugin versions prior to 2.3
Header Enhancement WordPress plugin versions prior to 1.5
Generate Child Theme WordPress plugin versions prior to 1.6
Essential Content Types WordPress plugin versions prior to 1.9
Catch Web Tools WordPress plugin versions prior to 2.7
Catch Under Construction WordPress plugin versions prior to 1.4
Catch Themes Demo Import WordPress plugin versions prior to 1.6
Catch Sticky Menu WordPress plugin versions prior to 1.7
Catch Scroll Progress Bar WordPress plugin versions prior to 1.6
Social Gallery and Widget WordPress plugin versions prior to 2.3
Catch Infinite Scroll WordPress plugin versions prior to 1.9
Catch Import Export WordPress plugin versions prior to 1.9
Catch Gallery WordPress plugin versions prior to 1.7
Catch Duplicate Switcher WordPress plugin versions prior to 1.6
Catch Breadcrumb WordPress plugin versions prior to 1.7
Catch IDs WordPress plugin versions prior to 2.4
Description:
The issue concerns multiple plugins from the CatchThemes vendor that do not perform capability and CSRF checks in the
ctp switch AJAX action. This could allow any authenticated users, such as subscribers, to change the configurations of the affected plugins.Recommendations:
For Essential Widgets WordPress plugin versions prior to 1.9, update to version 1.9 or later.
For To Top WordPress plugin versions prior to 2.3, update to version 2.3 or later.
For Header Enhancement WordPress plugin versions prior to 1.5, update to version 1.5 or later.
For Generate Child Theme WordPress plugin versions prior to 1.6, update to version 1.6 or later.
For Essential Content Types WordPress plugin versions prior to 1.9, update to version 1.9 or later.
For Catch Web Tools WordPress plugin versions prior to 2.7, update to version 2.7 or later.
For Catch Under Construction WordPress plugin versions prior to 1.4, update to version 1.4 or later.
For Catch Themes Demo Import WordPress plugin versions prior to 1.6, update to version 1.6 or later.
For Catch Sticky Menu WordPress plugin versions prior to 1.7, update to version 1.7 or later.
For Catch Scroll Progress Bar WordPress plugin versions prior to 1.6, update to version 1.6 or later.
For Social Gallery and Widget WordPress plugin versions prior to 2.3, update to version 2.3 or later.
For Catch Infinite Scroll WordPress plugin versions prior to 1.9, update to version 1.9 or later.
For Catch Import Export WordPress plugin versions prior to 1.9, update to version 1.9 or later.
For Catch Gallery WordPress plugin versions prior to 1.7, update to version 1.7 or later.
For Catch Duplicate Switcher WordPress plugin versions prior to 1.6, update to version 1.6 or later.
For Catch Breadcrumb WordPress plugin versions prior to 1.7, update to version 1.7 or later.
For Catch IDs WordPress plugin versions prior to 2.4, update to version 2.4 or later.
Exploit
Fix
Improper Access Control
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Catch Breadcrumb
Catch Duplicate Switcher
Catch Gallery
Catch Ids
Catch Import Export
Catch Infinite Scroll
Catch Scroll Progress Bar
Catch Sticky Menu
Catch Themes Demo Import
Catch Under Construction
Catch Web Tools
Essential Content Types
Essential Widgets