Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-15336
Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter
CVE-2022-0440
Catch Themes Demo Import < 2.1.1 - Admin+ Remote Code Execution
CVE-2021-39352
Catch Themes Demo Import <= 1.7 Admin+ Arbitrary File Upload
CVE-2021-24752
Multiple Plugins from CatchThemes - Unauthorised Plugin's Setting Change
CVE-2020-12054
The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16 themes (if the plugin is enabled) by the same author: Alchemist and Alchemist PRO, Izabel and Izabel PRO, Chique and Chique PRO, Clean Enterprise and Clean Enterprise PRO, Bold Photography PRO, Intuitive PRO, Devotepress PRO, Clean Blocks PRO, Foodoholic PRO, Catch Mag PRO, Catch Wedding PRO, and Higher Education PRO.
