Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2026-08-02
CVE-2026-16285 - Product Attachment For Woocommerce Plugin
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.
PLUGIN
Product Attachment For Woocommerce
CVE-2026-16285
Risk Score
