Catch Themes Demo Import <= 1.7 Admin+ Arbitrary File Upload
48Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 7.2epss 56%
from disclosure to weapon0 days
Published on NVDOct 21
metasploitOct 21
exploitation probability
56%top 1% of all CVEs
observed exploitation
nono source reports it
The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to upload malicious files that can be used to achieve remote code execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Catch Themes Demo Import · Catch Themes Demo ImportReferences
http://packetstormsecurity.com/files/165207/WordPress-Catch-Themes-Demo-Import-1.6.1-Shell-Upload.htmlhttp://packetstormsecurity.com/files/165463/WordPress-Catch-Themes-Demo-Import-Shell-Upload.htmlhttps://github.com/BigTiger2020/word-press/blob/main/Catch%20Themes%20Demo%20Import.mdhttps://github.com/Hacker5preme/Exploits/tree/main/Wordpress/CVE-2021-39352https://plugins.trac.wordpress.org/changeset/2617555/catch-themes-demo-import/trunk/inc/CatchThemesDemoImport.phphttps://www.exploit-db.com/exploits/50580https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39352