Executive brief
The Download Attachments plugin for WordPress, which allows users to manage and display file downloads on their websites, contains a security flaw. This vulnerability allows an unauthorized person to bypass access controls and potentially view or download files that were intended to be restricted. This could lead to the exposure of sensitive documents or internal information.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the dFactory Download Attachments plugin for WordPress through version 1.4.0. The flaw stems from an authorization bypass through a user-controlled key, allowing attackers to exploit incorrectly configured access control security levels. An unauthenticated remote attacker can manipulate input parameters to access or interact with attachments that should be restricted based on the plugin's security settings. As of the advisory date, no official patch has been confirmed, though users are advised to monitor for updates beyond version 1.4.0.
Affected products
- dFactory Download Attachments <= 1.4.0
Timeline
- 2026-01-11: other: Vulnerability reported by researcher Jakub Herman
- 2026-02-10: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD