Description
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post.
Published: 2026-09-05
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not validate a block attribute before using it as an HTML tag name in its gallery output. This flaw allows a user with the Author role or higher to inject arbitrary JavaScript that executes in the browsers of anyone who views the affected post, resulting in stored cross‑site scripting that can compromise confidentiality, integrity, and authenticity of the site.

Affected Systems

WordPress sites that have the CatFolders Document Gallery & PDF Library plugin installed with any version older than 2.0.7. The plugin vendor is unknown; the flaw affects all installations of that plugin regardless of WordPress version.

Risk and Exploitability

Because the exploit requires a user with Author privileges, the attack is confined to authenticated users. The vulnerability is persistent: once injected code appears in a post, every visitor to that post will have the script executed. No EPSS score is publicly available, and the flaw is not listed in the CISA KEV catalog, but the lack of input validation and the potential for widespread impact imply a high severity risk.

Generated by OpenCVE AI on September 5, 2026 at 07:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the CatFolders plugin to version 2.0.7 or later
  • Restrict the capabilities of the Author role so that such users can no longer add posts that could contain the block attribute injection
  • Apply a Web Application Firewall rule or other content‑security‑policy measures to block unexpected script tags from rendering in the gallery output

Generated by OpenCVE AI on September 5, 2026 at 07:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 05 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post.
Title CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-05T06:00:09.771Z

Reserved: 2026-09-02T16:15:07.256Z

Link: CVE-2026-84930

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T07:17:14.503

Modified: 2026-09-05T07:17:14.503

Link: CVE-2026-84930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T07:45:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')