PT-2021-22558 · WordPress · Catch Themes Demo Import

Published

2021-10-21

·

Updated

2022-02-28

·

CVE-2021-39352

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Catch Themes Demo Import WordPress plugin versions up to and including 1.7
Description: The issue is related to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, due to insufficient file type validation. This allows an attacker with administrative privileges to upload malicious files, potentially leading to remote code execution.
Recommendations: For versions up to and including 1.7, consider disabling the import functionality in the ~/inc/CatchThemesDemoImport.php file as a temporary workaround until a patch is available. Restrict access to the import functionality to minimize the risk of exploitation. Avoid using the import functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39352

Affected Products

Catch Themes Demo Import