Description
Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Attachments: from n/a through <= 1.4.0.
Published: 2026-04-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Protected Content
Action: Patch
AI Analysis

Impact

An authorization bypass in the dFactory Download Attachments plugin occurs when a user can construct a request that references files they are not permitted to download. This flaw allows confidential attachments to be exposed, effectively compromising the confidentiality of protected content. The weakness is a classic Insecure Direct Object Reference, classified as CWE‑639.

Affected Systems

This issue affects the WordPress plugin dFactory Download Attachments in every release up to and including version 1.4.0. Site administrators whose sites run this plugin should verify whether they host sensitive attachments that could be accessed through the download interface.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly confirmed exploits are currently known. The likely attack vector is inferred from the description as the manipulation of the download key or URL parameter that the plugin uses to locate files. If an attacker discovers a valid key, they can download any attachment that the plugin believes they own, requiring only basic knowledge of the plugin’s filename mapping. This could lead to unsolicited disclosure of private data from the affected WordPress site.

Generated by OpenCVE AI on April 14, 2026 at 16:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update dFactory Download Attachments plugin to a version newer than 1.4.0.
  • Verify that the plugin’s access control settings are correctly configured, ensuring that only authorized users can reference attachment keys.
  • Monitor access logs for unusual download activity before and after the patch.

Generated by OpenCVE AI on April 14, 2026 at 16:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 14 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Dfactory
Dfactory download Attachments
Wordpress
Wordpress wordpress
Vendors & Products Dfactory
Dfactory download Attachments
Wordpress
Wordpress wordpress

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Attachments: from n/a through <= 1.4.0.
Title WordPress Download Attachments plugin <= 1.4.0 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References

Subscriptions

Dfactory Download Attachments
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:52:02.578Z

Reserved: 2026-04-07T10:57:27.974Z

Link: CVE-2026-39616

cve-icon Vulnrichment

Updated: 2026-04-14T14:03:39.500Z

cve-icon NVD

Status : Deferred

Published: 2026-04-08T09:16:31.460

Modified: 2026-04-29T10:17:31.813

Link: CVE-2026-39616

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-14T16:39:02Z

Weaknesses