Vulnerability record · CVE-2022-0440 · published 7 March 2022
CVE-2022-0440: Catchplugins catch themes demo import unrestricted file upload vulnerability
Catchplugins · Catch Themes Demo Import
The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set to true)
Description
The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set to true)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wpscan.com/vulnerability/2239095f-8a66-4a5d-ab49-1662a40fddf1 | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/2239095f-8a66-4a5d-ab49-1662a40fddf1 | ExploitThird Party Advisory |
Track CVE-2022-0440 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-0440), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.