Catchplugins

    Dashboard / Vendors

    Products: 11
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-15336

    Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter

    Last Modified: Jul 17, 2026
    Published: Jul 16, 2026

    CVE-2022-0440

    Catch Themes Demo Import < 2.1.1 - Admin+ Remote Code Execution

    Last Modified: Nov 21, 2024
    Published: Mar 07, 2022

    CVE-2021-39352

    Catch Themes Demo Import <= 1.7 Admin+ Arbitrary File Upload

    Last Modified: Feb 14, 2025
    Published: Oct 21, 2021

    CVE-2021-24752

    Multiple Plugins from CatchThemes - Unauthorised Plugin's Setting Change

    Last Modified: Nov 21, 2024
    Published: Oct 18, 2021

    CVE-2020-12054

    The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16 themes (if the plugin is enabled) by the same author: Alchemist and Alchemist PRO, Izabel and Izabel PRO, Chique and Chique PRO, Clean Enterprise and Clean Enterprise PRO, Bold Photography PRO, Intuitive PRO, Devotepress PRO, Clean Blocks PRO, Foodoholic PRO, Catch Mag PRO, Catch Wedding PRO, and Higher Education PRO.

    Last Modified: Nov 21, 2024
    Published: Apr 23, 2020
    Items Per Page
    Catchplugins Vulnerabilities & Security CVEs | CVE-DB