PT-2026-33021 · Colbeinformatik · Katalogportal-Pdf-Sync Widget

Phong Nguyen

·

Publicado

2026-04-15

·

Atualizado

2026-04-24

·

CVE-2026-3649

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.0. The katalogportal popup shortcode() function is registered as an AJAX handler via wp ajax katalogportal shortcodePrinter but lacks any capability check (current user can()) or nonce verification. This allows any authenticated user, including Subscribers, to call the endpoint and retrieve a list of all synchronized PDF attachments (including those attached to private or draft posts) along with their titles, actual filenames, and the katalogportal userid configuration value. The WP Query uses post status => 'any' which returns attachments regardless of the parent post's visibility status.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3649

Produtos afetados

Katalogportal-Pdf-Sync Widget