ZeroHour

CVE-2026-81799

large

Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-81799 is a broken access control vulnerability (missing authorization, CWE-862) in the Return Refund and Exchange For WooCommerce WordPress plugin, affecting all versions up to and including 4.6.4. A privileged action in the plugin lacks a proper authorization check, so any unauthenticated visitor can trigger it over the network with no privileges or user interaction required. An attacker who does this can modify data managed by the plugin — plausibly return, refund, and exchange (RMA) request information — and the CVSS score (C:N/I:H/A:N) indicates integrity-only impact with no confidentiality loss or service disruption. Any WordPress/WooCommerce store running the plugin at version 4.6.4 or older is affected; sites without the plugin are not. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, and no in-the-wild exploitation is known.

What to do: Update Return Refund and Exchange For WooCommerce to the latest patched release (any version newer than 4.6.4). Until patched, deactivate the plugin or restrict unauthenticated access to its AJAX/REST endpoints, and review logs and existing return/refund/exchange records for signs of tampering. Since there is no public PoC or known exploitation yet, patching at the next maintenance cycle is reasonable unless the store is heavily exposed.

Affected
WP Swings Return Refund and Exchange For WooCommerce (WordPress plugin)<= 4.6.4
Estimated exposure
large~30,000 sites (tens of thousands of active installs of the free plugin on WordPress.org) — Estimated from the plugin's public WordPress.org active-install count (tens of thousands of WooCommerce shops); only a subset of those run unpatched 4.6.4-or-older versions, and paid/pro deployments are not counted.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.

Ecosystems
WordPress, E-commerce
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.