
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-16285 is an unauthenticated arbitrary media download vulnerability in the Product Attachment for WooCommerce WordPress plugin (by theDotstore), classified as a Missing Authorization flaw (CWE-862). The plugin fails to perform any authorization check before streaming media library files, enabling unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID. All versions before 2.3.3 are affected. The vulnerability was publicly disclosed on 2026-07-21 and assigned a CVSS score of 5.3 (Medium) (WPScan, Github Advisory).
The root cause is a missing authorization check (CWE-862 / OWASP A5: Broken Access Control) in the plugin's file-streaming functionality. When a request is made to download an attachment, the plugin streams the media library file directly without verifying whether the requesting user has permission to access it. An attacker can exploit this by supplying sequential or guessed numeric attachment IDs in the request, effectively enumerating the WordPress media library and downloading any file stored there — including those intentionally kept private or not linked from any public page. No authentication or special privileges are required (WPScan).
Successful exploitation results in unauthorized disclosure of files stored in the WordPress media library, including private documents, unlinked uploads, and any sensitive attachments managed through the WooCommerce product attachment plugin. An unauthenticated remote attacker can systematically enumerate numeric attachment IDs to download all accessible files, potentially exposing confidential business documents, customer data, invoices, or other sensitive materials. There is no direct integrity or availability impact, but the confidentiality breach could facilitate further attacks or regulatory compliance violations (WPScan, Github Advisory).
?attachment_id=1, ?attachment_id=2, etc.) to enumerate all media library files.woo-product-attachment) from unauthenticated sessions; HTTP 200 responses for attachment IDs that are not publicly linked.The vendor (theDotstore) has released a patched version: Product Attachment for WooCommerce 2.3.3. All site administrators running any version prior to 2.3.3 should update immediately via the WordPress plugin dashboard. As a temporary workaround until patching is possible, implement network-level or WAF-based access controls to restrict unauthenticated access to the plugin's file-streaming endpoints. Additionally, audit the WordPress media library for sensitive files that may have been exposed and consider relocating critical documents outside the web root (WPScan, Github Advisory).
The vulnerability was discovered and reported by researcher kevin (@OPCIA) and verified by WPScan. WPScan has followed a responsible disclosure timeline, withholding the full proof-of-concept until 2026-08-04 to allow site administrators time to apply the patch. No significant broader media coverage or notable community commentary beyond standard vulnerability database aggregation has been observed at this time (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."