# WP Attachments <= 6.0.3 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure via 'download' Parameter

- **ID:** WPSEC-2026-0473
- **Plugin:** WP Attachments – Smarter File Management & Download Lists (`wp-attachments`), https://wordpress.org/plugins/wp-attachments/
- **Affected versions:** from 4.0 before 6.1
- **Fixed in:** 6.1 (Update to 6.1 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-attachments
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0473/

## Description

The WP Attachments plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'download' parameter in versions 4.0 up to, and including, 6.0.3. When the 'Enable download counter' setting is on, the plugin's download link handler accepts any attachment ID and redirects to that attachment's file URL without checking whether the visitor can view the post the file is attached to. This makes it possible for unauthenticated attackers to enumerate attachment IDs and learn the file URLs of attachments belonging to private, draft, pending, scheduled or password-protected posts, and then retrieve those files from the revealed URLs.

## References

- https://wpsec.com/vuln/WPSEC-2026-0473/
- https://plugins.svn.wordpress.org/wp-attachments/tags/6.1/
- https://wordpress.org/plugins/wp-attachments/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0473/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
