Medium severity5.3NVD Advisory· Published Aug 13, 2026
CVE-2026-3835
CVE-2026-3835
Description
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the get_advance_file_by_url() method in all versions up to, and including, 2.8.8.8 The method uses a SQL LIKE operator for token lookup without escaping wildcard characters via $wpdb->esc_like(). This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as %) as the token value, matching any record in the plugin's file table and downloading any protected file.
Affected products
1- Range: <=2.8.8.8
Patches
Vulnerability mechanics
References
8- plugins.trac.wordpress.org/browser/prevent-direct-access/tags/2.8.8.4/includes/repository.phpnvd
- plugins.trac.wordpress.org/browser/prevent-direct-access/trunk/download.phpnvd
- plugins.trac.wordpress.org/browser/prevent-direct-access/trunk/includes/repository.phpnvd
- plugins.trac.wordpress.org/changeset/3637499/prevent-direct-access/trunk/includes/repository.phpnvd
- plugins.trac.wordpress.org/changesetnvd
- plugins.trac.wordpress.org/changesetnvd
- wordpress.org/plugins/prevent-direct-access/nvd
- www.wordfence.com/threat-intel/vulnerabilities/id/c39d16f1-ce80-402c-8a36-f9070dc5f9c9nvd
News mentions
0No linked articles in our index yet.