Answer in brief
CVE-2026-84930 records a Unknown severity vulnerability in CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute. The current sources do not mark it as known exploited. The current feed maps Unknown/CatFolders Document Gallery & PDF Library (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Unknown/CatFolders Document Gallery & PDF Library (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Unknown/CatFolders Document Gallery & PDF Librarygeneric | >=0 <2.0.7 | 2.0.7 |
Published upstream
Sep 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 5, 2026
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post.
Quoted source text, attributed separately from HOL analysis.