← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 13, 2026 · 06:17via CVEFeed

CVE-2026-3835 - Prevent Direct Access – Protect WordPress Files = 2.8.8.8 - Unauthenticated Protected File Access

Brief

CVE ID : CVE-2026-3835

Published : Aug. 13, 2026, 6:17 a. m.

  • 2 hours, 47 minutes ago

Description : The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.

  • 8. 8 The method uses a SQL `LIKE` operator for token lookup without escaping wildcard characters via `$wpdb-esc_like()`.

This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as `%`) as the token value, matching any record in the plugin's file table and downloading any protected file.

Severity: 5.3

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed