CVE-2026-16285: The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users t
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-16285
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-162850.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-16285 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Product Attachment for
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-61271: Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business…nvd · 2026-07-21
- mediumCVE-2026-60684: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (compone…nvd · 2026-07-21
- highCVE-2026-47028: Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business…nvd · 2026-07-21
- mediumCVE-2026-47009: Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, File…nvd · 2026-07-21
More from NVD Recent CVEs
- highCVE-2026-59913: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missin…2026-08-03
- highCVE-2026-59912: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Impro…2026-08-03
- unknownCVE-2026-38447: osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The …2026-08-03
- unknownCVE-2026-38446: A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sa…2026-08-03
- unknownCVE-2026-38444: osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header …2026-08-03