WordPress Plugin Vulnerabilities

WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download

Description

The plugin does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
kevin(@OPCIA)
Submitter
kevin(@OPCIA)
Verified
Yes

Timeline

Publicly Published
2026-07-21 (about 13 days ago)
Added
2026-07-21 (about 12 days ago)
Last Updated
2026-07-21 (about 12 days ago)

Other