SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-19717

HIGH · CVSS 7.5 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-16 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The CatFolders Document Gallery & PDF Library WordPress plugin prior to version 2.0.7 lacks proper authorization checks in certain REST API endpoints, enabling unauthenticated users to access sensitive information about media attachments, including their titles, types, sizes, and URLs. This vulnerability poses a risk of information disclosure, potentially exposing private media content. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized data access.

CVE
CVE-2026-19717
Severity
HIGH
CVSS
7.5
EPSS
0.35%
WordPress

Original NVD Description

The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allowing unauthenticated users to retrieve the title, type, size and URL of the media attachments assigned to any of its folders, including folders which are not published in any gallery on the site.