Ghostwire

CVE-2026-16285: The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before...

HIGH CVSS 0.0

Published: August 2, 2026 | Last Modified: August 2, 2026

Description

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References