CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute
Summary
| CVE | CVE-2026-84930 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-05 07:17:14 UTC |
| Updated | 2026-09-05 07:17:14 UTC |
| Description | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post. |
Risk And Classification
Problem Types: CWE-79 Cross-Site Scripting (XSS)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | CatFolders Document Gallery PDF Library | affected 2.0.7 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/c38b69f2-60cb-46b3-aa81-451ac062f5c7 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Artus KG (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.