CVE-2026-84930 PUBLISHED

CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute

Assigner: WPScan
Reserved: 02.09.2026 Published: 05.09.2026 Updated: 05.09.2026

The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post.

Product Status

Vendor Unknown
Product CatFolders Document Gallery & PDF Library
Versions Default: unaffected
  • affected from 0 to 2.0.7 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE