The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site.
Metrics
Affected Vendors & Products
References
History
Sun, 30 Aug 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Sun, 30 Aug 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Sat, 29 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Sat, 29 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site. | |
| Title | CatFolders Document Gallery Pro < 2.0.7 - Unauthenticated Missing Authorization via download-all | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-08-29T06:00:20.269Z
Updated: 2026-08-30T00:56:52.572Z
Reserved: 2026-08-10T12:39:41.681Z
Link: CVE-2026-19430
Updated: 2026-08-30T00:49:14.973Z
Status : Deferred
Published: 2026-08-29T06:17:24.857
Modified: 2026-08-31T20:14:36.250
Link: CVE-2026-19430
No data.