
PEACH
Un cadre d’isolation des locataires
CVE-2026-16285 is an unauthenticated arbitrary media download vulnerability in the Product Attachment for WooCommerce WordPress plugin (by theDotstore), classified as a Missing Authorization flaw (CWE-862). The plugin fails to perform any authorization check before streaming media library files, enabling unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID. All versions before 2.3.3 are affected. The vulnerability was publicly disclosed on 2026-07-21 and assigned a CVSS score of 5.3 (Medium) (WPScan, Github Advisory).
The root cause is a missing authorization check (CWE-862 / OWASP A5: Broken Access Control) in the plugin's file-streaming functionality. When a request is made to download an attachment, the plugin streams the media library file directly without verifying whether the requesting user has permission to access it. An attacker can exploit this by supplying sequential or guessed numeric attachment IDs in the request, effectively enumerating the WordPress media library and downloading any file stored there — including those intentionally kept private or not linked from any public page. No authentication or special privileges are required (WPScan).
Successful exploitation results in unauthorized disclosure of files stored in the WordPress media library, including private documents, unlinked uploads, and any sensitive attachments managed through the WooCommerce product attachment plugin. An unauthenticated remote attacker can systematically enumerate numeric attachment IDs to download all accessible files, potentially exposing confidential business documents, customer data, invoices, or other sensitive materials. There is no direct integrity or availability impact, but the confidentiality breach could facilitate further attacks or regulatory compliance violations (WPScan, Github Advisory).
?attachment_id=1, ?attachment_id=2, etc.) to enumerate all media library files.woo-product-attachment) from unauthenticated sessions; HTTP 200 responses for attachment IDs that are not publicly linked.The vendor (theDotstore) has released a patched version: Product Attachment for WooCommerce 2.3.3. All site administrators running any version prior to 2.3.3 should update immediately via the WordPress plugin dashboard. As a temporary workaround until patching is possible, implement network-level or WAF-based access controls to restrict unauthenticated access to the plugin's file-streaming endpoints. Additionally, audit the WordPress media library for sensitive files that may have been exposed and consider relocating critical documents outside the web root (WPScan, Github Advisory).
The vulnerability was discovered and reported by researcher kevin (@OPCIA) and verified by WPScan. WPScan has followed a responsible disclosure timeline, withholding the full proof-of-concept until 2026-08-04 to allow site administrators time to apply the patch. No significant broader media coverage or notable community commentary beyond standard vulnerability database aggregation has been observed at this time (WPScan).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."