Unauthorized Access Risk in Prevent Direct Access Plugin for WordPress
CVE-2026-3835

5.3MEDIUM

What is CVE-2026-3835?

The Prevent Direct Access plugin for WordPress is susceptible to unauthorized file access due to insufficient validation of input tokens. This vulnerability occurs in the get_advance_file_by_url() method, which improperly handles token lookups through SQL queries using the LIKE operator. The absence of proper escaping for wildcard characters allows unauthenticated attackers to craft tokens with wildcard elements, potentially gaining access to any protected file stored within the plugin's database. This security flaw affects all versions of the plugin up to and including 2.8.8.8, emphasizing the necessity for immediate user updates to mitigate this risk.

Affected Version(s)

Prevent Direct Access – Protect WordPress Files 0 <= 2.8.8.8

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucas Montes (NiRoX)
.