CVE-2026-3649 | colbeinformatik Katalogportal-pdf-sync Widget Plugin up to 1.0.0 on WordPress AJAX katalogportal_popup_shortcode katalogportal_userid authorization
A vulnerability was found in colbeinformatik Katalogportal-pdf-sync Widget Plugin up to 1.0.0 on WordPress. It has been declared as problematic. This affects the function katalogportal_popup_shortcode of the component AJAX Handler. The manipulation of the argument katalogportal_userid results in missing authorization.
This vulnerability was named CVE-2026-3649. The attack may be performed from remote. There is no available exploit.