CVE

CVE-2026-19717 — CatFolders Document Gallery & PDF Library [catfolders-document-gallery] < 2.0.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-19717 CatFolders Document Gallery & PDF Library [catfolders-document-gallery] < 2.0.7 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 2.0.7 2.0.7 2026-08-16

CVE-2026-19717

The CatFolders plugin for WordPress, prior to version 2.0.7, has a security flaw in its REST API endpoints, which allows anyone to access information about media files linked to specific folders, even if those folders are not publicly visible on the site, without needing to be authenticated. This vulnerability enables unauthorized users to obtain details about the media files, including their title, type, size, and URL, without any restrictions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.