PT-2025-6599 · WordPress · The Return Refund/Exchange For Woocommerce

Tim Coen

·

Published

2025-02-14

·

Updated

2025-02-14

·

CVE-2024-13692

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress versions up to, and including, 4.4.5
Description The issue allows unauthenticated attackers to exploit an Insecure Direct Object Reference vulnerability due to missing validation on a user-controlled key. This enables attackers to overwrite linked refund image attachments, overwrite refund request messages, overwrite order messages, and read order messages of other users.
Recommendations For versions up to, and including, 4.4.5, update to a version later than 4.4.5 to resolve the issue. As a temporary workaround, consider restricting access to the functions that handle refund image attachments, refund request messages, and order messages until a patch is available.

Fix

Improper Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13692

Affected Products

The Return Refund/Exchange For Woocommerce