Impact
The WP Attachments plugin contains a missing authorization flaw that allows attackers to bypass access controls and retrieve files that should be restricted. This broken access control can expose private or sensitive attachments, potentially compromising confidentiality. The vulnerability is mapped to CWE‑862, indicating an insufficient authorization check at the application level.
Affected Systems
All installations of the Marco Milesi WP Attachments plugin from unspecified earlier versions through version 5.2 are affected.
Risk and Exploitability
The CVSS score of 5.4 places the flaw in the moderate severity range, while the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Attackers would most likely use the plugin’s exposed endpoints within a WordPress site to download or view protected attachments.
OpenCVE Enrichment