What is CVE-2026-3835?
An unauthorized file access vulnerability exists in the Prevent Direct Access – Protect WordPress Files plugin for WordPress (versions ≤2.8.8.8) due to insufficient token validation in the `get_advance_file_by_url()` method using a SQL `LIKE` operator. Users should update to the latest patched version immediately.
Azərbaycanca: WordPress üçün Prevent Direct Access plaginində (≤2.8.8.8 versiyalar) `get_advance_file_by_url()` metodunda token yoxlanışının zəif olması səbəbindən qorunan fayllara icazəsiz giriş zəifliyi aşkarlanıb. SQL `LIKE` operatorunun istifadəsi bu boşluğa yol açır; plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the Prevent Direct Access plugin are affected by CVE-2026-3835?
Versions 2.8.8.8 and earlier of the Prevent Direct Access plugin for WordPress are affected by this vulnerability.
What is the root cause of CVE-2026-3835?
The vulnerability stems from insufficient token validation in the `get_advance_file_by_url()` method, where the use of a SQL `LIKE` operator leads to unauthorized access to protected files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.