Impact
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not validate a block attribute before using it as an HTML tag name in its gallery output. This flaw allows a user with the Author role or higher to inject arbitrary JavaScript that executes in the browsers of anyone who views the affected post, resulting in stored cross‑site scripting that can compromise confidentiality, integrity, and authenticity of the site.
Affected Systems
WordPress sites that have the CatFolders Document Gallery & PDF Library plugin installed with any version older than 2.0.7. The plugin vendor is unknown; the flaw affects all installations of that plugin regardless of WordPress version.
Risk and Exploitability
Because the exploit requires a user with Author privileges, the attack is confined to authenticated users. The vulnerability is persistent: once injected code appears in a post, every visitor to that post will have the script executed. No EPSS score is publicly available, and the flaw is not listed in the CISA KEV catalog, but the lack of input validation and the potential for widespread impact imply a high severity risk.
OpenCVE Enrichment