PatchSiren cyber security CVE debrief
CVE-2026-19717 CatFolders CVE debrief
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allowing unauthenticated users to retrieve the title, type, size and URL of the media attachments assigned to any of its folders, including folders which are not published in any gallery on the site. This vulnerability affects WordPress installations using the CatFolders plugin, particularly those with sensitive media attachments. Defenders should verify plugin configurations and review access controls for sensitive data. Evidence from the NVD and WPScan suggests that the CatFolders plugin is vulnerable to unauthorized access, allowing unauthenticated users to retrieve sensitive media attachment information.
- Vendor
- CatFolders
- Product
- Document Gallery & PDF Library
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-16
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-16
- Advisory updated
- 2026-08-26
Who should care
Defenders responsible for WordPress installations using the CatFolders Document Gallery & PDF Library plugin should prioritize patching to version 2.0.7 or later. This includes operators, platform administrators, vulnerability management teams, and security teams who need to ensure the plugin is updated and access controls are in place.
Technical summary
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 is vulnerable to unauthorized access due to missing authorisation checks in some of its REST API endpoints. This allows unauthenticated users to retrieve the title, type, size, and URL of media attachments assigned to any of its folders, including those not published in any gallery on the site. The vulnerability affects WordPress installations using the CatFolders plugin, particularly those with sensitive media attachments. Defenders should prioritize patching to version 2.0.7 or later and restrict access to sensitive data.
Defensive priority
Defenders should prioritize patching the CatFolders Document Gallery & PDF Library WordPress plugin to version 2.0.7 or later, and restrict access to sensitive data.
Recommended defensive actions
- Patch the CatFolders Document Gallery & PDF Library WordPress plugin to version 2.0.7 or later
- Restrict access to sensitive data
- Monitor for suspicious activity
- Verify plugin configuration
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Evidence from the NVD and WPScan suggests that the CatFolders plugin is vulnerable to unauthorized access, allowing unauthenticated users to retrieve sensitive media attachment information. The vulnerability affects the CatFolders Document Gallery & PDF Library WordPress plugin before version 2.0.7. Defenders should verify plugin configurations and review access controls for sensitive data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19717 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19717
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19717 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19717
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/79a4bae6-96e2-44b4-a56b-42198f8b3d32/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.