CVE-2026-19430

The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-29 06:17

Updated : 2026-08-31 20:14


NVD link : CVE-2026-19430

Mitre link : CVE-2026-19430

CVE.ORG link : CVE-2026-19430


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization