PT-2025-48001 · Unknown+1 · Woocommerce+1

Powpy

·

Published

2025-11-25

·

Updated

2025-11-25

·

CVE-2025-12634

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Refund Request for WooCommerce plugin for WordPress versions prior to 1.1
Description The Refund Request for WooCommerce plugin for WordPress has a flaw that allows unauthorized data modification. This is due to a missing capability check within the update refund status function. Authenticated attackers with Subscriber-level access or higher can exploit this to change refund statuses to approved or rejected.
Recommendations Update the Refund Request for WooCommerce plugin to version 1.1 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12634

Affected Products

Refund Request For Woocommerce
Woocommerce