Return Refund and Exchange For WooCommerce
cpe:2.3:a:wpswings:return_refund_and_exchange_for_woocommerce:*:*:*:*:wordpress:*:*
- <= 4.4.5
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Return Refund and Exchange for WooCommerce plugin, specifically in versions through 4.4.5. This vulnerability arises from inadequate validation of user-controlled keys, enabling unauthenticated attackers to manipulate various aspects of the refund process. Exploitation could lead to overwriting refund-related image attachments, modifying refund request messages, altering order communication, and accessing order messages from other users.
Exploitation of this vulnerability allows for unauthorized modification of refund requests and order messages, including attached images, potentially leading to misuse of the refund process and manipulation of order-related communications.
The vulnerability can be reproduced by sending a request to the WordPress site with a user-controlled key that is not properly validated. This can be done by an unauthenticated user, taking advantage of the missing validation to access and modify refund requests and order messages of other users.
Users are advised to update the Return Refund and Exchange for WooCommerce plugin to version 4.4.6 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.