A vulnerability marked as problematic has been reported in buildwps Prevent Direct Access Plugin up to 2.8.8.8 on WordPress. This vulnerability affects the function get_advance_file_by_url . Performing a manipulation of the argument token results in improper authorization. This vulnerability is reported as CVE-2026-3835 . The attack is possible to be carried out remotely. No exploit exists.