๐Ÿ” CVE Alert

CVE-2026-77695

MEDIUM 6.5

Woo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and Manipulation

CVSS Score
6.5
EPSS Score
0.2%
EPSS Percentile
6th

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return requests on any guest order.

Vendor unknown
Product return refund and exchange for woocommerce
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown return refund and exchange for woocommerce

Be the first to know when new medium vulnerabilities affecting unknown return refund and exchange for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Return Refund and Exchange For WooCommerce
4.4.6 < 4.6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/2b09bafa-d812-4247-8199-ce7f2dbac85e/

Credits

Shikhali Jamalzade WPScan