Confirmed.
Immediate work-around is to disable the "thread password" plugin on the attachment_display hook.
Disabling this will allow users who do not have the password to the thread to see attachments in that thread if someone gave them the URL of the attachment- this may or may not be a problem for you.
I don't see an immediate long-term solution, I will try to work on it when I get a chance.
|