WordPress Plugin Vulnerabilities
WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download
Description
The plugin does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
kevin(@OPCIA)
Submitter
kevin(@OPCIA)
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-21 (about 13 days ago)
Added
2026-07-21 (about 12 days ago)
Last Updated
2026-07-21 (about 12 days ago)