CVE-2026-16285 PUBLISHED

WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download

Assigner: WPScan
Reserved: 20.07.2026 Published: 02.08.2026 Updated: 02.08.2026

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.

Product Status

Vendor Unknown
Product Product Attachment for WooCommerce
Versions Default: unaffected
  • affected from 0 to 2.3.3 (excl.)

Credits

  • kevin(@OPCIA) finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE