Description
The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site.
Published:
2026-08-29
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sat, 29 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site. | |
| Title | CatFolders Document Gallery Pro < 2.0.7 - Unauthenticated Missing Authorization via download-all | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-29T06:00:20.269Z
Reserved: 2026-08-10T12:39:41.681Z
Link: CVE-2026-19430
No data.
Status : Received
Published: 2026-08-29T06:17:24.857
Modified: 2026-08-29T06:17:24.857
Link: CVE-2026-19430
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.