PT-2025-45557 · Unknown+1 · Woocommerce+1

Powpy

·

Published

2025-11-08

·

Updated

2025-11-08

·

CVE-2025-12621

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Flexible Refund and Return Order for WooCommerce plugin for WordPress versions through 1.0.42
Description The Flexible Refund and Return Order for WooCommerce plugin for WordPress has a flaw where data can be altered without proper authorization. This is caused by an incorrect capability check within the create refund function. Authenticated attackers possessing Contributor-level access or higher can change the status of refund requests, including approving or denying them.
Recommendations Update the Flexible Refund and Return Order for WooCommerce plugin to a version later than 1.0.42.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12621

Affected Products

Flexible Refund/Return Order For Woocommerce
Woocommerce