Vulnerabilities / WP Attachments / WPSEC-2026-0473

WP Attachments <= 6.0.3 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure via 'download' Parameter

Medium 5.3 CWE-639Fixed in 6.1
ID
WPSEC-2026-0473
Plugin
WP Attachments – Smarter File Management & Download Lists (wp-attachments)
Affected
from 4.0 before 6.1
Remediation
Update to 6.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-06
Attack surface
WP Attachments on WPSec AttackSurface
Fix released
Published

Description

The WP Attachments plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'download' parameter in versions 4.0 up to, and including, 6.0.3. When the 'Enable download counter' setting is on, the plugin's download link handler accepts any attachment ID and redirects to that attachment's file URL without checking whether the visitor can view the post the file is attached to. This makes it possible for unauthenticated attackers to enumerate attachment IDs and learn the file URLs of attachments belonging to private, draft, pending, scheduled or password-protected posts, and then retrieve those files from the revealed URLs.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0