Impact
The Catfolders Document Gallery Pro WordPress plugin prior to version 2.0.7 fails to authorize several REST API routes, and the token that identifies requested content can be forged by a client. This flaw allows any visitor to list and download the contents of folders that have never been published, effectively leaking private data without authentication. The weakness is a classic case of missing authorization coupled with predictable or forgeable credentials, enabling unauthorized data disclosure.
Affected Systems
Affected systems comprise the Catfolders Document Gallery Pro plugin installed on WordPress sites, specifically any installation running a version older than 2.0.7. No vendor name is formally listed, but the plugin’s code base is available through typical WordPress plugin repositories.
Risk and Exploitability
Risk and exploitability are significant because the attack requires only a crafted HTTP request to a REST endpoint; the plugin does not enforce any user authentication or role checks. The EPSS score is not published, and the vulnerability is not currently listed in CISA’s KEV catalog. Nonetheless, the ease of exploitation and the potential for sensitive data exposure make this a high‑priority issue for any site using the vulnerable plugin.
OpenCVE Enrichment