Impact
The vulnerability allows an unauthenticated attacker to bypass access restrictions within the Return Refund and Exchange For WooCommerce plugin. The compromised access control permits the attacker to initiate, modify or delete refund and exchange requests without proper authorization, potentially altering financial data or exfiltrating sensitive customer information. This weakness is a classic Broken Access Control scenario (CWE‑862).
Affected Systems
WordPress sites running WP Swings: Return Refund and Exchange For WooCommerce plugin version 4.6.4 or earlier are impacted. No other versions are affected.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KeV catalog, suggesting limited known exploitation but still a significant risk. The attack vector is inferred to be via the web application layer, as the control check is bypassed without any authentication requirement. Exploitation would require only a crafted request to the plugin’s refund endpoints.
OpenCVE Enrichment