WordPress security by component
CatFolders
Plugin description
CatFolders is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Dec 16, 2025; the highest published CVSS base score is 6.5.
Plugin slug:
catfoldersLatest vulnerability
CVE-2025-66120: CatFolders: A security weakness
CatFolders is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Dec 16, 2025 |
CVE-2025-66120
CatFolders: A security weakness
CatFolders is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 11, 2025 |
CVE-2025-9776
CatFolders – Tame Your WordPress Media Library by Category: SQL injection
CatFolders – Tame Your WordPress Media Library by Category is affected by SQL injection. Exploitation requires an authenticated author account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|