The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 29 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site. | |
| Title | CatFolders Document Gallery Pro < 2.0.7 - Unauthenticated Missing Authorization via download-all | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-29T06:00:20.269Z
Reserved: 2026-08-10T12:39:41.681Z
Link: CVE-2026-19430
No data.
Status : Received
Published: 2026-08-29T06:17:24.857
Modified: 2026-08-29T06:17:24.857
Link: CVE-2026-19430
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.