Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-15336 - Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter

CVE ID :CVE-2026-15336 Published : July 16, 2026, 4:17 a. m. | 38 minutes ago Description :The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.

3. This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activate_plugin GET parameter is present, calling Plugin_Upgrader::install() to download and install a plugin from WordPress.

Originally reported by CVE Recent
0 comments

0 comments

Posting as CrispCaracal876
0/1000

No comments yet. Be the first to start the discussion.