Junglewise Threat Intelligence

CVE-2026-77695: Return Refund and Exchange For WooCommerce privilege escalation in AJAX handlers

CVE-2026-77695 · Severity: medium · CVSS 6.5 · Published 2026-08-26

Executive brief

The Return Refund and Exchange For WooCommerce plugin fails to properly verify guest order ownership in its AJAX handlers exposed to unauthenticated users. An attacker can read private order messages, post messages and attachments impersonating customers, and cancel return requests on any guest order without authentication, compromising customer privacy and disrupting return/refund processes.

Technical details

The plugin's nopriv AJAX handlers (wps_rma_fetch_order_msgs, wps_rma_cancel_return_request, and others) verify guest order ownership using get_current_user_id() === $order->get_user_id(), which evaluates to 0 === 0 for any unauthenticated visitor. This allows attackers to enumerate sequential guest order IDs and exploit the flawed authorization check. An unauthenticated attacker can disclose private messages, post messages and attachments in a customer's name, and cancel return requests without any ownership verification. The vulnerability was fixed in version 4.6.4 by removing the guest path from certain handlers and implementing hash_equals() verification against the WooCommerce order_key.

Affected products

  • WP Speed Matters Woo Refund And Exchange Lite before 4.6.4

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Version 4.6.4 released

References