Commit 945a3d5eb8a for woocommerce

commit 945a3d5eb8a2e0528d6de92380223c6f400d4f30
Author: Rishabh Gupta <109821717+R1shabh-Gupta@users.noreply.github.com>
Date:   Wed Oct 7 17:32:53 2026 +0530

    Fix incorrect status codes in WC_Download_Handler (#67973)

    * Fix incorrect status codes in WC_Download_Handler

    * Add changelog entries for download handler status code fix

diff --git a/plugins/woocommerce/changelog/67561-fix-download-handler-status-codes b/plugins/woocommerce/changelog/67561-fix-download-handler-status-codes
new file mode 100644
index 00000000000..a89d10e181f
--- /dev/null
+++ b/plugins/woocommerce/changelog/67561-fix-download-handler-status-codes
@@ -0,0 +1,4 @@
+Significance: patch
+Type: fix
+
+Fix WC_Download_Handler: use the actual request protocol instead of a hardcoded HTTP/1.1 for range-download status headers, and default download errors to 403 Forbidden instead of 404 Not Found.
diff --git a/plugins/woocommerce/includes/class-wc-download-handler.php b/plugins/woocommerce/includes/class-wc-download-handler.php
index 9c316fd75a9..1f48006f1dc 100644
--- a/plugins/woocommerce/includes/class-wc-download-handler.php
+++ b/plugins/woocommerce/includes/class-wc-download-handler.php
@@ -570,7 +570,7 @@ class WC_Download_Handler {
 				);
 				self::download_file_redirect( $file_path );
 			} else {
-				self::download_error( __( 'File not found', 'woocommerce' ) );
+				self::download_error( __( 'File not found', 'woocommerce' ), '', 404 );
 			}
 		}

@@ -778,7 +778,7 @@ class WC_Download_Handler {

 		if ( isset( $download_range['is_range_request'] ) && true === $download_range['is_range_request'] ) {
 			if ( false === $download_range['is_range_valid'] ) {
-				header( 'HTTP/1.1 416 Requested Range Not Satisfiable' );
+				status_header( 416 );
 				header( 'Content-Range: bytes 0-' . ( $file_size - 1 ) . '/' . $file_size );
 				exit;
 			}
@@ -787,7 +787,7 @@ class WC_Download_Handler {
 			$end    = $download_range['start'] + $download_range['length'] - 1;
 			$length = $download_range['length'];

-			header( 'HTTP/1.1 206 Partial Content' );
+			status_header( 206 );
 			header( "Accept-Ranges: 0-$file_size" );
 			header( "Content-Range: bytes $start-$end/$file_size" );
 			header( "Content-Length: $length" );
@@ -984,7 +984,7 @@ class WC_Download_Handler {
 	 * @param string  $title   Error title.
 	 * @param integer $status  Error status.
 	 */
-	private static function download_error( $message, $title = '', $status = 404 ) {
+	private static function download_error( $message, $title = '', $status = 403 ) {
 		/*
 		 * Since we will now render a message instead of serving a download, we should unwind some of the previously set
 		 * headers.