plugin

Categorify Vulnerabilities

28 known security issues reported for the Categorify WordPress plugin. Most recent disclosed Sep 9, 2025.

12 medium

Running Categorify on your site? Check whether your installed version is affected.

Scan your site free

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] <= 1.0.7.5 (unfixed)

unknown

[en] Missing Authorization vulnerability in frenify Categorify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Categorify: from n/a through 1.0.7.5.

Affected:
up to 1.0.7.5
Fix:
No patched version reported
Disclosed:
Sep 9, 2025

CVE-2025-59005 on NVD →

Categorify <= 1.0.7.5 - Missing Authorization

medium

The Categorify – WordPress Media Library Category & File Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.7.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform...

CVSS:
4.3
Affected:
up to 1.0.7.5
Fix:
No patched version reported
Disclosed:
Sep 8, 2025

CVE-2025-59005 on NVD →

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.5

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.7.5

unknown

[en] The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxAddCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to add catego...

Affected:
up to 1.0.7.5
Fixed in:
1.0.7.5
Disclosed:
Mar 13, 2024

CVE-2024-0385 on NVD →

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.7.5

unknown

[en] The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxClearCategory function. This makes it possible for unauthenticated attackers to clear categories via a forged requ...

Affected:
up to 1.0.7.5
Fixed in:
1.0.7.5
Disclosed:
Feb 27, 2024

CVE-2024-1910 on NVD →

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.7.5

unknown

[en] The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxRenameCategory function. This makes it possible for unauthenticated attackers to rename categories via a forged re...

Affected:
up to 1.0.7.5
Fixed in:
1.0.7.5
Disclosed:
Feb 27, 2024

CVE-2024-1909 on NVD →

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.7.5

unknown

[en] The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxUpdateFolderPosition in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the...

Affected:
up to 1.0.7.5
Fixed in:
1.0.7.5
Disclosed:
Feb 27, 2024

CVE-2024-1653 on NVD →

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.7.5

unknown

[en] The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxDeleteCategory function. This makes it possible for unauthenticated attackers to delete categories via a forged re...

Affected:
up to 1.0.7.5
Fixed in:
1.0.7.5
Disclosed:
Feb 27, 2024

CVE-2024-1907 on NVD →

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.7.5

unknown

[en] The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxDeleteCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete...

Affected:
up to 1.0.7.5
Fixed in:
1.0.7.5
Disclosed:
Feb 27, 2024

CVE-2024-1649 on NVD →

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.7.5

unknown

[en] The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxUpdateFolderPosition function. This makes it possible for unauthenticated attackers to update the folder position...

Affected:
up to 1.0.7.5
Fixed in:
1.0.7.5
Disclosed:
Feb 27, 2024

CVE-2024-1912 on NVD →

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.7.5

unknown

[en] The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxAddCategory function. This makes it possible for unauthenticated attackers to add categories via a forged request...

Affected:
up to 1.0.7.5
Fixed in:
1.0.7.5
Disclosed:
Feb 27, 2024

CVE-2024-1906 on NVD →

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.7.5

unknown

[en] The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxRenameCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to rename...

Affected:
up to 1.0.7.5
Fixed in:
1.0.7.5
Disclosed:
Feb 27, 2024

CVE-2024-1650 on NVD →

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.7.5

unknown

[en] The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxClearCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to clear ca...

Affected:
up to 1.0.7.5
Fixed in:
1.0.7.5
Disclosed:
Feb 27, 2024

CVE-2024-1652 on NVD →

Categorify <= 1.0.7.4 - Missing Authorization in categorifyAjaxAddCategory

medium

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxAddCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to add categories.

CVSS:
4.3
Affected:
up to 1.0.7.4
Fixed in:
1.0.7.5
Disclosed:
Feb 26, 2024

CVE-2024-0385 on NVD →

Categorify <= 1.0.7.4 - Missing Authorization in categorifyAjaxRenameCategory

medium

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxRenameCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to rename categ...

CVSS:
4.3
Affected:
up to 1.0.7.4
Fixed in:
1.0.7.5
Disclosed:
Feb 26, 2024

CVE-2024-1650 on NVD →

Categorify <= 1.0.7.4 - Missing Authorization in categorifyAjaxDeleteCategory

medium

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxDeleteCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete categ...

CVSS:
4.3
Affected:
up to 1.0.7.4
Fixed in:
1.0.7.5
Disclosed:
Feb 26, 2024

CVE-2024-1649 on NVD →

Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxClearCategory

medium

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxClearCategory function. This makes it possible for unauthenticated attackers to clear categories via a forged request g...

CVSS:
4.3
Affected:
up to 1.0.7.4
Fixed in:
1.0.7.5
Disclosed:
Feb 26, 2024

CVE-2024-1910 on NVD →

Categorify <= 1.0.7.4 - Missing Authorization in categorifyAjaxClearCategory

medium

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxClearCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to clear categor...

CVSS:
4.3
Affected:
up to 1.0.7.4
Fixed in:
1.0.7.5
Disclosed:
Feb 26, 2024

CVE-2024-1652 on NVD →

Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxAddCategory

medium

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxAddCategory function. This makes it possible for unauthenticated attackers to add categories via a forged request grant...

CVSS:
4.3
Affected:
up to 1.0.7.4
Fixed in:
1.0.7.5
Disclosed:
Feb 26, 2024

CVE-2024-1906 on NVD →

Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxUpdateFolderPosition

medium

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxUpdateFolderPosition function. This makes it possible for unauthenticated attackers to update the folder position of ca...

CVSS:
4.3
Affected:
up to 1.0.7.4
Fixed in:
1.0.7.5
Disclosed:
Feb 26, 2024

CVE-2024-1912 on NVD →

Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxRenameCategory

medium

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxRenameCategory function. This makes it possible for unauthenticated attackers to rename categories via a forged request...

CVSS:
4.3
Affected:
up to 1.0.7.4
Fixed in:
1.0.7.5
Disclosed:
Feb 26, 2024

CVE-2024-1909 on NVD →

Categorify <= 1.0.7.4 - Missing Authorization in categorifyAjaxUpdateFolderPosition

medium

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxUpdateFolderPosition in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the fold...

CVSS:
4.3
Affected:
up to 1.0.7.4
Fixed in:
1.0.7.5
Disclosed:
Feb 26, 2024

CVE-2024-1653 on NVD →

Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxDeleteCategory

medium

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxDeleteCategory function. This makes it possible for unauthenticated attackers to delete categories via a forged request...

CVSS:
4.3
Affected:
up to 1.0.7.4
Fixed in:
1.0.7.5
Disclosed:
Feb 26, 2024

CVE-2024-1907 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.5

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Mar 4, 2022

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.5

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Categorify – WordPress Media Library Category & File Manager plugin (versions <= 1.0.4).

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Feb 28, 2022

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.5

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Categorify – WordPress Media Library Category & File Manager plugin (versions <= 1.0.4).

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Feb 28, 2022

Categorify &#8211; WordPress Media Library Category &amp; File Manager [categorify] < 1.0.6

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.0.6
Fixed in:
1.0.6

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database