CVE-2021-24752
The To Top plugin before version 2.3, along with multiple other CatchThemes vendor plugins, contains a vulnerability in the ctp_switch AJAX action that lacks proper capability and CSRF protections. This flaw allows any authenticated user, including those with minimal Subscriber privileges, to modify plugin configurations without proper authorization. The vulnerability affects numerous CatchThemes plugins across various versions, enabling unauthorized changes to essential plugin settings by low-privileged account holders.
Based on public CVE data (MITRE/NVD).