{
 "id": "WPSEC-2026-0473",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0473/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0473/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0473/index.md",
 "title": "WP Attachments <= 6.0.3 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure via 'download' Parameter",
 "description": "The WP Attachments plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'download' parameter in versions 4.0 up to, and including, 6.0.3. When the 'Enable download counter' setting is on, the plugin's download link handler accepts any attachment ID and redirects to that attachment's file URL without checking whether the visitor can view the post the file is attached to. This makes it possible for unauthenticated attackers to enumerate attachment IDs and learn the file URLs of attachments belonging to private, draft, pending, scheduled or password-protected posts, and then retrieve those files from the revealed URLs.",
 "plugin": {
  "slug": "wp-attachments",
  "name": "WP Attachments",
  "full_name": "WP Attachments – Smarter File Management & Download Lists",
  "wordpress_org": "https://wordpress.org/plugins/wp-attachments/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-attachments/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-attachments"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "4.0",
    "from_inclusive": true,
    "to": "6.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 4.0 before 6.1"
  ]
 },
 "introduced_in": "4.0",
 "fixed_in": "6.1",
 "remediation": "Update to 6.1 or later.",
 "fix_released": "2026-10-05T12:46:06+00:00",
 "published": "2026-10-06T19:43:53+00:00",
 "updated": "2026-10-06T19:05:39.603801+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0473/",
  "https://plugins.svn.wordpress.org/wp-attachments/tags/6.1/",
  "https://wordpress.org/plugins/wp-attachments/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-attachments",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-06"
 }
}