CVE-2026-3835 - Prevent Direct Access – Protect WordPress Files = 2.8.8.8 - Unauthenticated Protected File Access
Brief
CVE ID : CVE-2026-3835
Published : Aug. 13, 2026, 6:17 a. m.
- 2 hours, 47 minutes ago
Description : The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.
- 8. 8 The method uses a SQL `LIKE` operator for token lookup without escaping wildcard characters via `$wpdb-esc_like()`.
This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as `%`) as the token value, matching any record in the plugin's file table and downloading any protected file.
Severity: 5.3
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
