PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19430 Catfolders CVE debrief

The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site. This could potentially lead to unauthorized access to sensitive information. The CVE record was published on 2026-08-29T06:17:24.857Z and has not been modified since then. Users should review their plugin versions and update to 2.0.7 or later. Limited information is available about the potential impact and affected scope. Defenders should verify the official CVE record and assess their exposure. The evidence provided is limited; verify with primary official records.

Vendor
Catfolders
Product
Document Gallery Pro
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-29
Original CVE updated
2026-08-29
Advisory published
2026-08-29
Advisory updated
2026-08-29

Who should care

Users of Catfolders Document Gallery Pro WordPress plugin versions before 2.0.7 should be aware of this vulnerability. This includes site administrators, security teams, and operators responsible for maintaining WordPress installations with this plugin. They should assess their exposure and take necessary actions to protect their sites. Vulnerability management and security teams should prioritize patching or mitigating this vulnerability to prevent potential unauthorized access to folder contents. Additionally, operators and platform administrators should review their current configurations and update or restrict access as needed to prevent exploitation. Monitoring and detection teams should also be prepared to identify potential exploitation attempts and review logs for exposed assets that need extra review. Asset inventory management should include tracking of affected plugin versions for remediation prioritization. Rollback/change window planning may be necessary for affected systems, and source tracking should be implemented to monitor for potential changes or updates related to this vulnerability. Compensating controls, such as restricting access to REST API routes or implementing additional security measures, may be necessary while remediation is scheduled and verified. This vulnerability may require compensating controls for exposed systems while remediation is scheduled and verified. Monitoring and detection teams should review relevant logs for exposed assets that need extra review. Asset inventory management should track affected plugin versions for remediation prioritization. Rollback/change window planning may be necessary for affected systems. Source tracking should be implemented to monitor for potential changes or updates related to this vulnerability. Compensating controls may be necessary for exposed systems while remediation is scheduled and verified. Monitoring and detection teams should review relevant logs for exposed assets that need extra review. Asset inventory management should track affected plugin versions for remediation prioritization. Rollback/change window planning may be necessary for affected systems. Source tracking should be

Technical summary

The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site. This could potentially lead to unauthorized access to sensitive information. Users should review their plugin versions and update to 2.0.7 or later.

Defensive priority

Unauthenticated users may list and download folder contents using vulnerable REST API routes.

Recommended defensive actions

  • Inventory vulnerable plugin versions
  • Restrict access to REST API routes
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The evidence provided is limited; verify with primary official records. The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side. Limited information is available about the potential impact and affected scope. Defenders should verify the official CVE record and assess their exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19430 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19430

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19430 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19430

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.