CVE-2026-3649
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Apr 15, 2026
Vendor
unknown
Description
The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.0. The katalogportal_popup_shortcode() function is registered as an AJAX handler via wp_ajax_katalogportal_shortcodePrinter but lacks any capability check (current_user_can()) or nonce verification. This allows any authenticated user, including Subscribers, to call the endpoint and retrieve a list of all synchronized PDF attachments (including those attached to private or draft posts) along with their titles, actual filenames, and the katalogportal_userid configuration value. The WP_Query uses post_status => 'any' which returns attachments regardless of the parent post's visibility status.
References
- https://plugins.trac.wordpress.org/browser/katalogportal-pdf-sync/tags/1.0.0/inc/class.admin.php#L12
- https://plugins.trac.wordpress.org/browser/katalogportal-pdf-sync/tags/1.0.0/inc/class.admin.php#L209
- https://plugins.trac.wordpress.org/browser/katalogportal-pdf-sync/trunk/inc/class.admin.php#L12
- https://plugins.trac.wordpress.org/browser/katalogportal-pdf-sync/trunk/inc/class.admin.php#L209
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a01e7b21-f3ff-42a8-b78a-ad69973eda01?source=cve