Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-39352
HistoryOct 21, 2021 - 8:15 p.m.

Design/Logic Flaw

2021-10-2120:15:00
PRIOn knowledge base
www.prio-n.com
6

7.2 High

AI Score

Confidence

High

0.936 High

EPSS

Percentile

99.1%

The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to upload malicious files that can be used to achieve remote code execution.

CPENameOperatorVersion
catch_themes_demo_importle1.7

7.2 High

AI Score

Confidence

High

0.936 High

EPSS

Percentile

99.1%