cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcategorify categorify

Direction: ascending
Jun 07, 2024

Categorify – WordPress Media Library Category & File Manager # CVE-2024-1653

CVE, Research URL

CVE-2024-1653

Date
Feb 27, 2024
Research Description
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxUpdateFolderPosition in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the folder position of categories as well as update the metadata of other taxonomies.
Affected versions
Min -, max -.
Status
vulnerable

Categorify – WordPress Media Library Category & File Manager # CVE-2024-1907

CVE, Research URL

CVE-2024-1907

Date
Feb 27, 2024
Research Description
The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxDeleteCategory function. This makes it possible for unauthenticated attackers to delete categories via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable

Categorify – WordPress Media Library Category & File Manager # CVE-2024-1650

CVE, Research URL

CVE-2024-1650

Date
Feb 27, 2024
Research Description
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxRenameCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to rename categories.
Affected versions
Min -, max -.
Status
vulnerable

Categorify – WordPress Media Library Category & File Manager # CVE-2024-1906

CVE, Research URL

CVE-2024-1906

Date
Feb 27, 2024
Research Description
The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxAddCategory function. This makes it possible for unauthenticated attackers to add categories via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable

Categorify – WordPress Media Library Category & File Manager # CVE-2024-1912

CVE, Research URL

CVE-2024-1912

Date
Feb 27, 2024
Research Description
The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxUpdateFolderPosition function. This makes it possible for unauthenticated attackers to update the folder position of categories as well as update the metadata of other taxonomies via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable

Categorify – WordPress Media Library Category & File Manager # CVE-2024-1649

CVE, Research URL

CVE-2024-1649

Date
Feb 27, 2024
Research Description
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxDeleteCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete categories.
Affected versions
Min -, max -.
Status
vulnerable

Categorify – WordPress Media Library Category & File Manager # CVE-2024-1909

CVE, Research URL

CVE-2024-1909

Date
Feb 27, 2024
Research Description
The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxRenameCategory function. This makes it possible for unauthenticated attackers to rename categories via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable

Categorify – WordPress Media Library Category & File Manager # 66dfc1eb8614e77e9d8d099a1eefe7e4d6f43c2e

Date
Feb 28, 2022
Research Description
Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.6 WordPress Categorify – WordPress Media Library Category & File Manager plugin <= 1.0.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Categorify – WordPress Media Library Category & File Manager plugin (versions <= 1.0.4).
Affected versions
Min -, max -.
Status
vulnerable

Categorify &#8211; WordPress Media Library Category &amp; File Manager # CVE-2024-1652

CVE, Research URL

CVE-2024-1652

Date
Feb 27, 2024
Research Description
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxClearCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to clear categories.
Affected versions
Min -, max -.
Status
vulnerable

Categorify &#8211; WordPress Media Library Category &amp; File Manager # CVE-2024-0385

CVE, Research URL

CVE-2024-0385

Date
Mar 13, 2024
Research Description
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxAddCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to add categories.
Affected versions
Min -, max -.
Status
vulnerable

Categorify &#8211; WordPress Media Library Category &amp; File Manager # CVE-2024-1910

CVE, Research URL

CVE-2024-1910

Date
Feb 27, 2024
Research Description
The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxClearCategory function. This makes it possible for unauthenticated attackers to clear categories via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Nov 15, 2024

Categorify &#8211; WordPress Media Library Category &amp; File Manager # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
Min -, max -.
Status
vulnerable
Sep 10, 2025

Categorify &#8211; WordPress Media Library Category &amp; File Manager # CVE-2025-59005

CVE, Research URL

CVE-2025-59005

Date
Sep 09, 2025
Research Description
Missing Authorization vulnerability in frenify Categorify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Categorify: from n/a through 1.0.7.5.
Affected versions
Min -, max -.
Status
vulnerable