CVE-2026-16285: WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16285?
CVE-2026-16285 has a risk rating of 68, indicating a medium severity vulnerability.
How do I fix CVE-2026-16285?
To fix CVE-2026-16285, update the WooCommerce Product Attachment plugin to version 2.3.3 or later.
What types of files are at risk in CVE-2026-16285?
CVE-2026-16285 exposes all types of media files stored in the WooCommerce media library, including private or unlinked attachments.
Who can exploit CVE-2026-16285?
CVE-2026-16285 can be exploited by unauthenticated users who can guess the numeric IDs of media files.
What impact does CVE-2026-16285 have on websites?
CVE-2026-16285 allows unauthorized access to download sensitive media files, potentially leading to data exposure.