Executive brief
The Catch Themes Demo Import plugin for WordPress, which helps website owners import sample content, contains a security flaw that allows low-level users to install a specific additional plugin without permission. While this does not allow for full site takeover, it permits unauthorized changes to the site's installed software. This could lead to minor operational disruptions or the introduction of unwanted features on the website.
Technical details
The Catch Themes Demo Import plugin for WordPress is vulnerable to missing authorization due to an insecure implementation of the catch_themes_demo_import_activate_plugin() function. This function is hooked to admin_init and triggers when the activate_plugin GET parameter is present. The root cause is that the code calls Plugin_Upgrader::install() to download and install a plugin from WordPress.org before verifying the user's capabilities via current_user_can('activate_plugins'). An authenticated attacker with subscriber-level permissions or higher can exploit this to force the installation of the hardcoded 'essential-content-types' plugin. The vulnerability is present in versions up to and including 3.3.
Affected products
- Catch Plugins Catch Themes Demo Import up to, and including, 3.3
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory
References
- https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.2/inc/demo-importer.php
- https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.2/inc/demo-importer.php
- https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.2/inc/demo-importer.php
- https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.2/inc/demo-importer.php
- https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.3/inc/demo-importer.php
- https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.3/inc/demo-importer.php
- https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.3/inc/demo-importer.php