Return Refund and Exchange For WooCommerce
cpe:2.3:a:wpswings:return_refund_and_exchange_for_woocommerce:*:*:*:*:wordpress:*:*
- <= 4.5.5
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Return Refund and Exchange for WooCommerce plugin for WordPress, affecting all versions through 4.5.5. The vulnerability arises in the 'wps_rma_fetch_order_msgs()' function, where insufficient validation on a user-controlled key allows authenticated attackers with Subscriber-level access and above to read order messages from other users.
Exploitation of this vulnerability could lead to unauthorized access to order messages, allowing attackers to read private communications between customers and store owners.
Users are advised to update the plugin to version 4.5.6 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.