Return Refund and Exchange for WooCommerce Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Return Refund and Exchange for WooCommerce plugin for WordPress, affecting all versions through 4.5.5. The vulnerability arises in the 'wps_rma_fetch_order_msgs()' function, where insufficient validation on a user-controlled key allows authenticated attackers with Subscriber-level access and above to read order messages from other users.

Impact

Exploitation of this vulnerability could lead to unauthorized access to order messages, allowing attackers to read private communications between customers and store owners.

Remediation

Users are advised to update the plugin to version 4.5.6 or a newer patched version.

Added: Nov 21, 2025, 8:26 AM
Updated: Nov 21, 2025, 3:59 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
5.7
remediation
7.7
relevance
1.1
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.