CVE-2026-19717
Received Received - Intake

Unauthenticated Media Attachment Exposure in CatFolders WordPress Plugin

Vulnerability report for CVE-2026-19717, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-16

Last updated on: 2026-08-16

Assigner: WPScan

Description

The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allowing unauthenticated users to retrieve the title, type, size and URL of the media attachments assigned to any of its folders, including folders which are not published in any gallery on the site.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-16
Last Modified
2026-08-16
Generated
2026-08-16
AI Q&A
2026-08-16
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
catfolders document_gallery_pdf_library to 2.0.7 (exc)
catfolders document_gallery to 2.0.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-19717 is a vulnerability in the CatFolders Document Gallery & PDF Library WordPress plugin before version 2.0.7. It lacks authorization checks in some REST API endpoints, allowing unauthenticated users to access sensitive information about media attachments in folders, including unpublished ones.

Detection Guidance

To detect this vulnerability, check if your WordPress site is running the CatFolders Document Gallery & PDF Library plugin version before 2.0.7. You can verify the plugin version via the WordPress admin panel under Plugins or by inspecting the plugin files. Additionally, monitor network traffic for unauthorized REST API requests targeting the plugin's endpoints.

Impact Analysis

This vulnerability allows attackers to retrieve details like titles, types, sizes, and URLs of media files in folders, even those not publicly accessible. This could expose sensitive data such as private documents or files not meant for public viewing.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by exposing sensitive media attachment details such as titles, types, sizes, and URLs without proper authorization. Unauthorized access to such data may violate privacy requirements under these regulations.

Mitigation Strategies

Immediately update the CatFolders Document Gallery & PDF Library plugin to version 2.0.7 or later. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Ensure your WordPress installation and all plugins are regularly updated to prevent similar vulnerabilities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19717. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart