CVE-2025-12086: Return Refund and Exchange For WooCommerce <= 4.5.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Refund Request Cancellation
The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the 'wpsrmacancelreturnrequest' AJAX endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete other users refund requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12086?
CVE-2025-12086 has a medium severity rating due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-12086?
To fix CVE-2025-12086, update the Return Refund and Exchange For WooCommerce plugin to version 4.5.6 or later.
What versions are affected by CVE-2025-12086?
CVE-2025-12086 affects all versions of the Return Refund and Exchange For WooCommerce plugin up to and including 4.5.5.
What is CVE-2025-12086?
CVE-2025-12086 is a vulnerability in the Return Refund and Exchange For WooCommerce plugin that allows for Insecure Direct Object Reference due to inadequate validation.
Who is impacted by CVE-2025-12086?
Users of the Return Refund and Exchange For WooCommerce plugin for WordPress who have versions up to 4.5.5 are impacted by CVE-2025-12086.