PT-2021-16253 · Catch Themes · Catch Gallery+12

Apple502J

·

Published

2021-10-18

·

Updated

2022-10-25

·

CVE-2021-24752

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Essential Widgets WordPress plugin versions prior to 1.9 To Top WordPress plugin versions prior to 2.3 Header Enhancement WordPress plugin versions prior to 1.5 Generate Child Theme WordPress plugin versions prior to 1.6 Essential Content Types WordPress plugin versions prior to 1.9 Catch Web Tools WordPress plugin versions prior to 2.7 Catch Under Construction WordPress plugin versions prior to 1.4 Catch Themes Demo Import WordPress plugin versions prior to 1.6 Catch Sticky Menu WordPress plugin versions prior to 1.7 Catch Scroll Progress Bar WordPress plugin versions prior to 1.6 Social Gallery and Widget WordPress plugin versions prior to 2.3 Catch Infinite Scroll WordPress plugin versions prior to 1.9 Catch Import Export WordPress plugin versions prior to 1.9 Catch Gallery WordPress plugin versions prior to 1.7 Catch Duplicate Switcher WordPress plugin versions prior to 1.6 Catch Breadcrumb WordPress plugin versions prior to 1.7 Catch IDs WordPress plugin versions prior to 2.4
Description: The issue concerns multiple plugins from the CatchThemes vendor that do not perform capability and CSRF checks in the ctp switch AJAX action. This could allow any authenticated users, such as subscribers, to change the configurations of the affected plugins.
Recommendations: For Essential Widgets WordPress plugin versions prior to 1.9, update to version 1.9 or later. For To Top WordPress plugin versions prior to 2.3, update to version 2.3 or later. For Header Enhancement WordPress plugin versions prior to 1.5, update to version 1.5 or later. For Generate Child Theme WordPress plugin versions prior to 1.6, update to version 1.6 or later. For Essential Content Types WordPress plugin versions prior to 1.9, update to version 1.9 or later. For Catch Web Tools WordPress plugin versions prior to 2.7, update to version 2.7 or later. For Catch Under Construction WordPress plugin versions prior to 1.4, update to version 1.4 or later. For Catch Themes Demo Import WordPress plugin versions prior to 1.6, update to version 1.6 or later. For Catch Sticky Menu WordPress plugin versions prior to 1.7, update to version 1.7 or later. For Catch Scroll Progress Bar WordPress plugin versions prior to 1.6, update to version 1.6 or later. For Social Gallery and Widget WordPress plugin versions prior to 2.3, update to version 2.3 or later. For Catch Infinite Scroll WordPress plugin versions prior to 1.9, update to version 1.9 or later. For Catch Import Export WordPress plugin versions prior to 1.9, update to version 1.9 or later. For Catch Gallery WordPress plugin versions prior to 1.7, update to version 1.7 or later. For Catch Duplicate Switcher WordPress plugin versions prior to 1.6, update to version 1.6 or later. For Catch Breadcrumb WordPress plugin versions prior to 1.7, update to version 1.7 or later. For Catch IDs WordPress plugin versions prior to 2.4, update to version 2.4 or later.

Exploit

Fix

Improper Access Control

CSRF

Weakness Enumeration

Related Identifiers

CVE-2021-24752

Affected Products

Catch Breadcrumb
Catch Duplicate Switcher
Catch Gallery
Catch Ids
Catch Import Export
Catch Infinite Scroll
Catch Scroll Progress Bar
Catch Sticky Menu
Catch Themes Demo Import
Catch Under Construction
Catch Web Tools
Essential Content Types
Essential Widgets