Description
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
Published: 2026-09-10
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized Control of Refund Operations and Potential Data Exposure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to bypass access restrictions within the Return Refund and Exchange For WooCommerce plugin. The compromised access control permits the attacker to initiate, modify or delete refund and exchange requests without proper authorization, potentially altering financial data or exfiltrating sensitive customer information. This weakness is a classic Broken Access Control scenario (CWE‑862).

Affected Systems

WordPress sites running WP Swings: Return Refund and Exchange For WooCommerce plugin version 4.6.4 or earlier are impacted. No other versions are affected.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KeV catalog, suggesting limited known exploitation but still a significant risk. The attack vector is inferred to be via the web application layer, as the control check is bypassed without any authentication requirement. Exploitation would require only a crafted request to the plugin’s refund endpoints.

Generated by OpenCVE AI on September 10, 2026 at 15:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Return Refund and Exchange For WooCommerce plugin to the latest version (4.6.5 or newer) to eliminate the broken access control flaw.
  • If an upgrade is not immediately possible, disable the refund and exchange features or remove the plugin entirely to prevent unauthenticated access.
  • Configure web application firewall rules or access restrictions to block unauthenticated requests to refund and exchange endpoints while a permanent fix is applied.

Generated by OpenCVE AI on September 10, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
Title WordPress Return Refund and Exchange For WooCommerce plugin <= 4.6.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-10T15:09:34.829Z

Reserved: 2026-08-27T12:24:38.075Z

Link: CVE-2026-81799

cve-icon Vulnrichment

Updated: 2026-09-10T15:09:15.410Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T15:17:46.230

Modified: 2026-09-10T16:17:58.487

Link: CVE-2026-81799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:30:06Z

Weaknesses