Executive brief
Return Refund and Exchange For WooCommerce is a popular WordPress plugin that manages product returns, refunds, and exchanges for online stores. A broken access control vulnerability allows unauthenticated attackers to access and perform actions they should not be permitted to do, potentially exposing customer refund data or enabling unauthorized refund requests without proper authorization.
Technical details
The vulnerability is a broken access control flaw in Return Refund and Exchange For WooCommerce plugin versions 4.6.4 and earlier. The plugin fails to properly validate user permissions, allowing unauthenticated attackers to access sensitive pages or perform restricted actions via the network. An attacker can view other users' data, initiate unauthorized refunds, or manipulate exchange requests without authentication. No official patch is currently available; mitigation rules have been issued to block attacks until a fix is released.
Affected products
- Woo Return Refund and Exchange For WooCommerce <= 4.6.4
Timeline
- 2026-09-08: disclosed
- 2026-09-10: advisory