---
id: CVE-2026-19430
title: >-
  The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not
  authorise some of its REST API routes, and the token identifying the requested
  content is forgeable client side, allowing unauthenticated users to list and
  downlo…
summary: >-
  The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not
  authorise some of its REST API routes, and the token identifying the requested
  content is forgeable client side, allowing unauthenticated users to list and
  downlo…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-862
published: '2026-08-29'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19430'
references:
  - url: 'https://wpscan.com/vulnerability/ebf45bc7-a782-48b6-99ca-25bc78697e20/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00193
epssPercentile: 0.07979
ingestedAt: '2026-08-30T07:49:07.072Z'
---

## Overview

The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
