What is CVE-2026-16285?
CVE-2026-16285 affects the Product Attachment for WooCommerce plugin before version 2.3.3. It fails to perform authorization checks before streaming media files, allowing unauthenticated users to download any attachment, including private or unlinked uploads, by brute-forcing numeric IDs. Sites using this plugin should immediately update to version 2.3.3 or later.
Azərbaycanca: CVE-2026-16285, Product Attachment for WooCommerce plagininin 2.3.3-dən əvvəlki versiyalarına təsir edir. Plugin media fayllarını yayımlamazdan əvvəl heç bir avtorizasiya yoxlaması aparmır, bu da autentifikasiya olunmamış şəxslərə rəqəmsal ID-ləri sıralamaqla özəl və ya əlaqələndirilməmiş faylları yükləməyə imkan verir. Plagindən istifadə edən saytlar dərhal 2.3.3 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Product Attachment for WooCommerce plugin are vulnerable to CVE-2026-16285?
CVE-2026-16285 affects the plugin versions prior to 2.3.3.
How can an unauthenticated user exploit CVE-2026-16285 to access files?
Because the plugin does not perform authorization checks before streaming media files, an unauthenticated user can download private or unlinked uploads by brute-forcing numeric IDs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.