CatFolders Document Gallery & PDF Library WordPress 插件在 2.0.7 版本之前,其部分 REST API 端点缺乏身份验证检查,导致未经身份验证的用户可以检索分配给任意文件夹的媒体附件的标题、类型、大小和 URL,包括那些未在站点任何画廊中发布的文件夹。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | CatFolders Document Gallery & PDF Library | < 2.0.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | CatFolders Document Gallery & PDF Library | 0 ~ 2.0.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19726 | Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure | |
| CVE-2026-19728 | Extra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Di | |
| CVE-2026-19725 | WPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_con | |
| CVE-2026-18653 | WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter | |
| CVE-2026-19712 | Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description | |
| CVE-2026-19613 | ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source | |
| CVE-2026-19714 | Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Au | |
| CVE-2026-19711 | Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount W | |
| CVE-2026-15384 | Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOR | |
| CVE-2026-13712 | Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL | |
| CVE-2026-17533 | All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Cod |
No comments yet