VYPR

Product Attachment for WooCommerce

by WordPress

CVEs (2)

  • CVE-2023-40212MedOct 3, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versions.

  • CVE-2026-16285Aug 2, 2026
    risk 0.00cvss epss 0.00

    The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric…