CVE-2026-16285

CVE-2026-16285: WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download

Vendor Unknown
Product Product Attachment for WooCommerce
Published August 2, 2026
Last update August 3, 2026

CVSS base score

What the vulnerability does

01Description

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.

Key dates

02Disclosure timeline

August 2, 2026 CVE published
August 3, 2026 Record updated