Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Refund and Return Order for WooCommerce flexible-refund-and-return-order-for-woocommerce allows Stored XSS.This issue affects Flexible Refund and Return Order for WooCommerce: from n/a through <= 1.0.51.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Neutralization of Input During Web Page Generation, resulting in a Stored Cross‑Site Scripting flaw in the Flexible Refund and Return Order for WooCommerce plugin. The likely attack vector involves injecting JavaScript, as the plugin stores refund and return data without proper sanitization; it is inferred that a malicious user can insert arbitrary script that persists and later renders to other users, giving attackers the ability to hijack sessions, steal credentials, or perform other malicious actions in the context of the victim’s browser. The weakness is identified as CWE‑79. The impact includes potential confidentiality, integrity, and availability compromises for users interacting with the affected WordPress site.

Affected Systems

The flaw affects the wpdesk Flexible Refund and Return Order for WooCommerce plugin for all WordPress installations running any version up through 1.0.51 inclusive. Sites hosting the plugin on these or earlier releases are vulnerable regardless of the WordPress core version. Any user who can create or edit refunds or returns via the plugin’s interface may trigger stored data that will be rendered unsanitized.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity risk. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, implying a low probability of exploitation so far. Based on the description, it is inferred that an attacker could potentially exploit the vulnerability from the public web by submitting a crafted refund or return order that stores malicious payloads, which would later be rendered when the page is viewed. The likely attack vector does not require privileged access; once the data is stored, any user who views the affected page can be victimized.

Generated by OpenCVE AI on July 31, 2026 at 11:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Flexible Refund and Return Order for WooCommerce plugin to the latest version that fixes the stored XSS flaw.
  • If an update is not immediately available, deactivate or uninstall the plugin to eliminate the vulnerability.
  • Deploy a web application firewall or security plugin configured to filter common XSS payloads, such as <script> tags and event handlers, from being stored in the plugin’s form inputs.
  • Limit user capabilities by restricting refund and return creation to trusted roles, reducing the chance that untrusted users can inject malicious scripts.

Generated by OpenCVE AI on July 31, 2026 at 11:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdesk
Wpdesk flexible Refund And Return Order For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wpdesk
Wpdesk flexible Refund And Return Order For Woocommerce

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Refund and Return Order for WooCommerce flexible-refund-and-return-order-for-woocommerce allows Stored XSS.This issue affects Flexible Refund and Return Order for WooCommerce: from n/a through <= 1.0.51.
Title WordPress Flexible Refund and Return Order for WooCommerce plugin <= 1.0.51 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wpdesk Flexible Refund And Return Order For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:52.935Z

Reserved: 2026-06-24T12:46:27.804Z

Link: CVE-2026-57402

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:26.951Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')