Unrated severityNVD Advisory· Published Aug 2, 2026· Updated Aug 3, 2026
WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download
CVE-2026-16285
Description
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.3.3
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/99a3a0a4-0e82-4388-88b2-72bd822904b5/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.