Junglewise Threat Intelligence

CVE-2026-57402: wpdesk Flexible Refund and Return Order for WooCommerce Stored XSS

CVE-2026-57402 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Executive brief

A security vulnerability exists in the Flexible Refund and Return Order for WooCommerce plugin, which is used by online stores to manage customer returns. An attacker with a customer-level account can inject malicious scripts into the website. If a store administrator views the affected data, the script could allow the attacker to redirect users to malicious sites, display unauthorized advertisements, or potentially perform actions on behalf of the administrator.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the wpdesk Flexible Refund and Return Order for WooCommerce plugin through version 1.0.51. The issue stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with 'Customer' level privileges can submit malicious payloads that are stored on the server. When a site administrator or other privileged user interacts with the crafted content, the script executes in their browser context. This can lead to session hijacking or unauthorized administrative actions. The vulnerability is addressed in version 1.0.52.

Affected products

  • wpdesk Flexible Refund and Return Order for WooCommerce <= 1.0.51

Timeline

  • 2026-04-28: disclosed: Reported by hhhai
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD published date
  • 2026-07-08: patched: Version 1.0.52 released

References