Impact
The vulnerability arises because the Return Refund and Exchange For WooCommerce plugin does not verify the ownership of guest orders in certain AJAX actions. This flaw allows unauthenticated users to read private order messages, post new messages and attachments as if they were the customer, and cancel return requests on any guest order.
Affected Systems
Any WordPress site running the Return Refund and Exchange For WooCommerce plugin with a version earlier than 4.6.4 is vulnerable. This includes all installations that have the plugin installed and have not applied the 4.6.4 update or later.
Risk and Exploitability
The flaw can be exploited by an attacker without authentication simply by sending crafted AJAX requests. No CVSS score is provided, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, but because the attack is trivial and the impact is significant, the risk is high.
OpenCVE Enrichment