CVE-2026-84930: CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute
Published Sep 5, 2026
·Updated
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post.
Affected Software
1 affected component
WordPress plugin CatFolders Document Gallery & PDF Library<2.0.7
Event History
Sep 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Which users can exploit this issue?
A user with the WordPress Author role or any higher-privileged role can exploit it by supplying a malicious value for the affected block attribute.
2
Who is exposed to the injected script?
Anyone who views a post containing the malicious gallery output may have the injected script execute in their browser.
3
Which plugin versions are affected?
Versions of CatFolders Document Gallery & PDF Library earlier than 2.0.7 are affected.