Junglewise Threat Intelligence

CVE-2026-81799: Return Refund and Exchange For WooCommerce broken access control

CVE-2026-81799 · Severity: high · CVSS 7.5 · Published 2026-09-10

Executive brief

Return Refund and Exchange For WooCommerce is a popular WordPress plugin that manages product returns, refunds, and exchanges for online stores. A broken access control vulnerability allows unauthenticated attackers to access and perform actions they should not be permitted to do, potentially exposing customer refund data or enabling unauthorized refund requests without proper authorization.

Technical details

The vulnerability is a broken access control flaw in Return Refund and Exchange For WooCommerce plugin versions 4.6.4 and earlier. The plugin fails to properly validate user permissions, allowing unauthenticated attackers to access sensitive pages or perform restricted actions via the network. An attacker can view other users' data, initiate unauthorized refunds, or manipulate exchange requests without authentication. No official patch is currently available; mitigation rules have been issued to block attacks until a fix is released.

Affected products

  • Woo Return Refund and Exchange For WooCommerce <= 4.6.4

Timeline

  • 2026-09-08: disclosed
  • 2026-09-10: advisory

References