Catch Themes Demo Import
Catch Themes Demo Import has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 2 high. 2021 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 2 of the records (50%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type.
Every one of the 4 issues recorded for Catch Themes Demo Import has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, one record each. Catch Themes Demo Import is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2022-0440Catch Themes Demo Import <= 2.1 - Authenticated (Admin+) Arbitrary File Upload
Read the full analysisVulnerability Records

Catch Themes Demo Import
Author
Catch Plugins
Catch Themes Demo Import is a free demo importer WordPress plugin that lets you import the demo you desire in just a single click. The plugin works out of the box; all you have to do is install and activate the plugin and all the demos available on your currently used theme will be on your fingertips (visit Appearance=> Import Demo Data). If the theme doesn’t have any predefined import files, you’ll have to upload three files – a demo content XML file for content import, a WIE/JSON file for widget import, and a DAT file for customizer import. With the plugin activated, whether you have predefined demo files available or not, you’ll be able to import demos on your website without any hesitancy. Download Catch Themes Demo Import today and start importing theme demos to your website without affecting your wallet! Are you a theme author? Setup Catch Themes Demo Import for your theme and your users will thank you for it! This plugin will create a submenu page under Appearance with the title Import demo data. If the theme you are using does not have any predefined import files, then you will be presented with three file upload inputs. First one is required and you will have to upload a demo content XML file, for the actual demo import. The second one is optional and will ask you for a WIE or JSON file for widgets import. You create that file using the Widget Importer & Exporter plugin. The third one is also optional and will import the customizer settings, select the DAT file which you can generate from Catch Import Export plugin (the customizer settings will be imported only if the export file was created from the same theme). The final one is optional as well and will import your Redux framework settings. You can generate the export json file with the Redux framework plugin. This plugin is using the improved WP import 2.0 that is still in development and can be found here: https://github.com/humanmade/WordPress-Importer. All progress of this plugin’s work is logged in a log file in the default WP upload directory, together with the demo import files used in the importing process. NOTE: There is no setting to “connect” authors from the demo import file to the existing users in your WP site (like there is in the original WP Importer plugin). All demo content will be imported under the current user.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C