Catchplugins develops a portfolio of WordPress plugins and themes focused on UI components, navigation, and demo functionality, with disclosed vulnerabilities clustering around file-upload handling, cross-site request forgery, and web-based input-validation issues typical of WordPress ecosystem plugins. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Catchplugins over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39352HIGH The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up | Oct 21, 2021 | 7.2 | 66 | NO | YES |
CVE-2020-12054MEDIUM The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16 themes (if the plugin is enabled) by the same | Apr 23, 2020 | 6.1 | 26 | NO | YES |
CVE-2026-15336MEDIUM The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the catch_themes_demo_import_activate | Jul 16, 2026 | 4.3 | 25 | NO | NO |
CVE-2022-0440HIGH The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP fil | Mar 7, 2022 | 7.2 | 24 | NO | NO |
CVE-2021-24752MEDIUM Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber | Oct 18, 2021 | 5.7 | 20 | NO | NO |
CVE-2024-31279MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Catch Plugins Generate Child Theme.This issue affects Generate Child Theme: from n/a through 2.0. | Apr 12, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Catchplugins.
Media articles that mention a CVE ID that affects a product developed by Catchplugins — matched by CVE ID, not by vendor name.