CVE-2026-19430
Last modified
CVE-2026-19430 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Catfolders Document Gallery Pro | >= 2.0.6, < 2.0.7 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-19430?
How severe is CVE-2026-19430?
How do I fix CVE-2026-19430?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19423The Ultimate Member WordPress plugin before 2.13.0 does not…8.1
- CVE-2026-19424Chiline Cloud developed by Inventec Appliances has a Insecur…7.5
- CVE-2026-19425Travel Agency Management System developed by Win Men Interma…9.8
- CVE-2026-19426POS System developed by FitSoft has a Missing Authentication…8.2
- CVE-2026-19429Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-1943The YayMail – WooCommerce Email Customizer plugin for WordPr…4.4
- CVE-2026-19433Authorization Bypass Through User-Controlled Key in the cont…8.6
- CVE-2026-19434Cross-site Scripting in the finding renderer in maalfer Pent…5.1
- CVE-2026-19435The Duplicate Post WordPress plugin before 1.5.6 does not ch…2.7
- CVE-2026-19436The Ultimate Gift Cards for WooCommerce WordPress plugin bef…7.5
- CVE-2026-19437IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …9.8
- CVE-2026-19439The Ultimate Gift Cards for WooCommerce WordPress plugin bef…7.5
Are you affected by CVE-2026-19430?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
