The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the 'attachment' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/attachment directory which can contain file attachments for order refunds.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Feb 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpswings
Wpswings return Refund And Exchange For Woocommerce |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:wpswings:return_refund_and_exchange_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpswings
Wpswings return Refund And Exchange For Woocommerce |
Fri, 14 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 14 Feb 2025 05:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the 'attachment' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/attachment directory which can contain file attachments for order refunds. | |
Title | Return Refund and Exchange For WooCommerce <= 4.4.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-14T15:24:27.609Z
Reserved: 2025-01-22T23:46:34.907Z
Link: CVE-2024-13641

Updated: 2025-02-14T15:24:23.229Z

Status : Analyzed
Published: 2025-02-14T06:15:19.957
Modified: 2025-02-25T19:39:47.477
Link: CVE-2024-13641

No data.