The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 via several functions due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite linked refund image attachments, overwrite refund request message, overwrite order messages, and read order messages of other users.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Feb 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpswings
Wpswings return Refund And Exchange For Woocommerce |
|
Weaknesses | CWE-639 | |
CPEs | cpe:2.3:a:wpswings:return_refund_and_exchange_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpswings
Wpswings return Refund And Exchange For Woocommerce |
Fri, 14 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 14 Feb 2025 05:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 via several functions due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite linked refund image attachments, overwrite refund request message, overwrite order messages, and read order messages of other users. | |
Title | Return Refund and Exchange For WooCommerce <= 4.4.5 - Authenticated (Subscriber+) Insecure Direct Object Reference | |
Weaknesses | CWE-285 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-14T15:46:13.565Z
Reserved: 2025-01-23T20:27:10.879Z
Link: CVE-2024-13692

Updated: 2025-02-14T15:36:39.563Z

Status : Analyzed
Published: 2025-02-14T06:15:20.140
Modified: 2025-02-25T19:40:09.050
Link: CVE-2024-13692

No data.