Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

Clear filters

2 vulnerability records

MediumCVE-2021-24752

CatchThemes Plugins (Various Versions) - Missing Authorization

Header Enhancement: Currently marked unpatchedGenerate Child Theme: Currently marked unpatchedSocial Gallery and Widget: Currently marked unpatchedCatch Import Export: Currently marked unpatchedCatch Under Construction: Currently marked unpatchedCatch Duplicate Switcher: Currently marked unpatchedCatch IDs: Currently marked unpatchedCatch Sticky Menu: Currently marked unpatchedEssential Widgets: Currently marked unpatchedCatch Infinite Scroll: Currently marked unpatchedTo Top: Currently marked unpatchedCatch Themes Demo Import: Currently marked unpatchedCatch Breadcrumb: Currently marked unpatchedEssential Content Types: Currently marked unpatchedCatch Gallery: Currently marked unpatchedCatch Web Tools: Currently marked unpatchedCatch Scroll Progress Bar: Currently marked unpatched

Affected versions: [*, 1.5); [*, 1.6); [*, 2.3); [*, 1.9); [*, 1.4); [*, 1.6); [*, 2.4); [*, 1.7)

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before 1.5, Generate Child Theme WordPress plugin before 1.6, Essential Content Types WordPress plugin before 1.9, Catch Web Tools WordPress plugin before 2.7, Catch Under Construction WordPress plugin before 1.4, Catch Themes Demo Import WordPress plugin before 1.6, Catch Sticky Menu WordPress plugin before 1.7, Catch Scroll Progress Bar WordPress plugin before 1.6, Social Gallery and Widget WordPress plugin before 2.3, Catch Infinite Scroll WordPress plugin before 1.9, Catch Import Export WordPress plugin before 1.9, Catch Gallery WordPress plugin before 1.7, Catch Duplicate Switcher WordPress plugin before 1.6, Catch Breadcrumb WordPress plugin before 1.7, Catch IDs WordPress plugin before 2.4's configurations.

Header Enhancement

Affected versions: [*, 1.5)

Patched versions: 1.5

Generate Child Theme

Affected versions: [*, 1.6)

Patched versions: 1.6

Social Gallery and Widget

Affected versions: [*, 2.3)

Patched versions: 2.3

Catch Import Export

Affected versions: [*, 1.9)

Patched versions: 1.9

Catch Under Construction

Affected versions: [*, 1.4)

Patched versions: 1.4

Catch Duplicate Switcher

Affected versions: [*, 1.6)

Patched versions: 1.6

Catch IDs

Affected versions: [*, 2.4)

Patched versions: 2.4

Catch Sticky Menu

Affected versions: [*, 1.7)

Patched versions: 1.7

Essential Widgets

Affected versions: [*, 1.9)

Patched versions: 1.9

Catch Infinite Scroll

Affected versions: [*, 1.9)

Patched versions: 1.9

To Top

Affected versions: [*, 2.3)

Patched versions: 2.3

Catch Themes Demo Import

Affected versions: [*, 1.6)

Patched versions: 1.6

Catch Breadcrumb

Affected versions: [*, 1.7)

Patched versions: 1.7

Essential Content Types

Affected versions: [*, 1.9)

Patched versions: 1.9

Catch Gallery

Affected versions: [*, 1.7)

Patched versions: 1.7

Catch Web Tools

Affected versions: [*, 2.7)

Patched versions: 2.7

Catch Scroll Progress Bar

Affected versions: [*, 1.6)

Patched versions: 1.6

Researcher credit: apple502j

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
September 20, 2021
CVSS
5.4
MediumCVE-2020-12054

Catch Breadcrumb <= 1.5.4 - Reflected Cross-Site Scripting

Catch Breadcrumb: Currently marked unpatched

Affected versions: [*, 1.5.5)

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16 themes (if the plugin is enabled) by the same author: Alchemist and Alchemist PRO, Izabel and Izabel PRO, Chique and Chique PRO, Clean Enterprise and Clean Enterprise PRO, Bold Photography PRO, Intuitive PRO, Devotepress PRO, Clean Blocks PRO, Foodoholic PRO, Catch Mag PRO, Catch Wedding PRO, and Higher Education PRO.

Catch Breadcrumb

Affected versions: [*, 1.5.5)

Patched versions: 1.5.5

Researcher credit: ΞX.MI

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 22, 2020
CVSS
6.1

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.