WordPress · Catfolders Document Gallery & Pdf Library · CVE-2026-19717
**Name of the Vulnerable Software and Affected Versions**
CatFolders Document Gallery & PDF Library WordPress plugin versions prior to 2.0.7
**Description**
Lack of authorization checks in certain REST API endpoints allows unauthenticated users to retrieve sensitive information about media attachments. This includes the title, type, size, and URL of attachments assigned to any folder, even those not published in a site gallery.
**Recommendations**
Update the plugin to version 2.0.7 or later.