PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19717 CatFolders CVE debrief

The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allowing unauthenticated users to retrieve the title, type, size and URL of the media attachments assigned to any of its folders, including folders which are not published in any gallery on the site. This vulnerability affects WordPress installations using the CatFolders plugin, particularly those with sensitive media attachments. Defenders should verify plugin configurations and review access controls for sensitive data. Evidence from the NVD and WPScan suggests that the CatFolders plugin is vulnerable to unauthorized access, allowing unauthenticated users to retrieve sensitive media attachment information.

Vendor
CatFolders
Product
Document Gallery & PDF Library
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-16
Original CVE updated
2026-08-26
Advisory published
2026-08-16
Advisory updated
2026-08-26

Who should care

Defenders responsible for WordPress installations using the CatFolders Document Gallery & PDF Library plugin should prioritize patching to version 2.0.7 or later. This includes operators, platform administrators, vulnerability management teams, and security teams who need to ensure the plugin is updated and access controls are in place.

Technical summary

The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 is vulnerable to unauthorized access due to missing authorisation checks in some of its REST API endpoints. This allows unauthenticated users to retrieve the title, type, size, and URL of media attachments assigned to any of its folders, including those not published in any gallery on the site. The vulnerability affects WordPress installations using the CatFolders plugin, particularly those with sensitive media attachments. Defenders should prioritize patching to version 2.0.7 or later and restrict access to sensitive data.

Defensive priority

Defenders should prioritize patching the CatFolders Document Gallery & PDF Library WordPress plugin to version 2.0.7 or later, and restrict access to sensitive data.

Recommended defensive actions

  • Patch the CatFolders Document Gallery & PDF Library WordPress plugin to version 2.0.7 or later
  • Restrict access to sensitive data
  • Monitor for suspicious activity
  • Verify plugin configuration
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

Evidence from the NVD and WPScan suggests that the CatFolders plugin is vulnerable to unauthorized access, allowing unauthenticated users to retrieve sensitive media attachment information. The vulnerability affects the CatFolders Document Gallery & PDF Library WordPress plugin before version 2.0.7. Defenders should verify plugin configurations and review access controls for sensitive data.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19717 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19717

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19717 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19717

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.