Return Refund and Exchange for WooCommerce Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Return Refund and Exchange for WooCommerce plugin for WordPress, affecting all versions through 4.5.5. The vulnerability arises in the 'wps_rma_cancel_return_request' AJAX endpoint, where insufficient validation on a user-controlled key allows authenticated attackers with Subscriber-level access and above to delete refund requests belonging to other users.

Impact

Exploitation of this vulnerability allows for unauthorized cancellation of refund requests, potentially leading to financial loss or disruption of service for affected users.

Remediation

Users can update to version 4.5.6 or a newer patched version to address this vulnerability.

Added: Nov 21, 2025, 8:34 AM
Updated: Nov 21, 2025, 4:08 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
6.1
remediation
7.7
relevance
1.1
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.