Executive brief
Order Cancellation & Returns for WooCommerce is a WordPress plugin that lets store managers and customers process refunds and order cancellations in WooCommerce shops. A flaw in the plugin's access control allows attackers to manipulate request parameters to access or modify other users' orders without proper authorization. An attacker could view, cancel, or manipulate orders belonging to other customers or the store.
Technical details
The vulnerability is an Insecure Direct Object References (IDOR) flaw in the order cancellation workflow, where the plugin fails to properly validate that the authenticated user has permission to access the order being requested. By modifying a user-controlled identifier or key in the request (such as an order ID or nonce), an attacker can bypass access control checks and interact with orders belonging to other users. The vulnerability requires only a subscriber-level account (low privilege) and can be exploited over the network. An authenticated attacker can view sensitive order data or trigger cancellations for arbitrary orders. The issue has been patched in version 1.1.13.
Affected products
- YoOhw Studio Order Cancellation & Returns for WooCommerce through 1.1.12
Timeline
- 2025-10-13: disclosed: Reported by powpy
- 2025-12-31: advisory: Published by Patchstack and NVD
- 2025-12-31: patched: Fixed in version 1.1.13