Feed/CVE-2026-16285
CVE-2026-16285

CVE-2026-16285

Published Aug 2, 2026·Updated Aug 2, 2026

NVD Description

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free