Wordpress Alert: Paid-download authorization bypass
A file link works without checking purchase or membership rights. Paid files may be shared publicly.
What it looks like
A file link works without checking purchase or membership rights.
Why it matters
Paid files may be shared publicly.
What to check
Verify download authorization on every request, not only when links are issued.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities, OWASP path traversal reference.
- Categories: WordPress
- Tags: #WordPress Security, #Plugin Security