CyberRota Analysis
AI-GeneratedThe CatFolders Document Gallery & PDF Library WordPress plugin prior to version 2.0.7 lacks proper authorization checks in certain REST API endpoints, enabling unauthenticated users to access sensitive information about media attachments, including their titles, types, sizes, and URLs. This vulnerability poses a risk of information disclosure, potentially exposing private media content. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized data access.
Original NVD Description
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allowing unauthenticated users to retrieve the title, type, size and URL of the media attachments assigned to any of its folders, including folders which are not published in any gallery on the site.