Description
The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site.
Published: 2026-08-29
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Catfolders Document Gallery Pro WordPress plugin prior to version 2.0.7 fails to authorize several REST API routes, and the token that identifies requested content can be forged by a client. This flaw allows any visitor to list and download the contents of folders that have never been published, effectively leaking private data without authentication. The weakness is a classic case of missing authorization coupled with predictable or forgeable credentials, enabling unauthorized data disclosure.

Affected Systems

Affected systems comprise the Catfolders Document Gallery Pro plugin installed on WordPress sites, specifically any installation running a version older than 2.0.7. No vendor name is formally listed, but the plugin’s code base is available through typical WordPress plugin repositories.

Risk and Exploitability

Risk and exploitability are significant because the attack requires only a crafted HTTP request to a REST endpoint; the plugin does not enforce any user authentication or role checks. The EPSS score is not published, and the vulnerability is not currently listed in CISA’s KEV catalog. Nonetheless, the ease of exploitation and the potential for sensitive data exposure make this a high‑priority issue for any site using the vulnerable plugin.

Generated by OpenCVE AI on August 29, 2026 at 08:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Catfolders Document Gallery Pro to version 2.0.7 or later.
  • Configure the site to restrict or remove access to the vulnerable REST API endpoints, for example by adding firewall rules or using a WordPress security plugin that blocks anonymous REST requests to the plugin’s routes.
  • If an immediate update is not feasible, implement a temporary workaround by requiring authenticated access for the plugin’s REST interfaces or disabling them entirely via site configuration.

Generated by OpenCVE AI on August 29, 2026 at 08:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sat, 29 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site.
Title CatFolders Document Gallery Pro < 2.0.7 - Unauthenticated Missing Authorization via download-all
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-29T06:00:20.269Z

Reserved: 2026-08-10T12:39:41.681Z

Link: CVE-2026-19430

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-29T06:17:24.857

Modified: 2026-08-29T06:17:24.857

Link: CVE-2026-19430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T08:30:06Z

Weaknesses