Executive brief
Catfolders Document Gallery Pro is a WordPress plugin that manages document folders and galleries. The plugin's REST API endpoints lack proper access controls and use forgeable encryption tokens, allowing unauthenticated attackers to list, search, and download private folder contents without any authentication or authorization checks.
Technical details
The vulnerability is a broken access control issue in the REST API routes of Catfolders Document Gallery Pro. The plugin fails to properly authorize requests to endpoints like catfdoc-reload-table and download-all, and uses client-side forgeable AES-256-CBC encrypted tokens to identify content. The encryption employs an unauthenticated IV transmitted alongside the ciphertext, allowing attackers to flip IV bytes to predictably modify the decrypted folder ID. An unauthenticated attacker can request arbitrary folders, receive encrypted tokens, manipulate the IV to target unpublished folders, and use the modified tokens to access private content through the download endpoint. The vulnerability was patched in version 2.0.7, which now properly enforces HTTP 403 authorization checks on all such requests.
Affected products
- Catfolders Document Gallery Pro before 2.0.7
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Version 2.0.7 released