CVE-2025-12621: Flexible Refund and Return Order for WooCommerce <= 1.0.42 - Incorrect Authorization to Authenticated (Contributor+) Refund Status Update
The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'createrefund' function in all versions up to, and including, 1.0.42. This makes it possible for authenticated attackers, with Contributor-level access and above, to update the status of refund requests, including approving and refusing refunds.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12621?
CVE-2025-12621 is classified as a high severity vulnerability due to the potential for unauthorized data modification.
How do I fix CVE-2025-12621?
To fix CVE-2025-12621, update the Flexible Refund and Return Order for WooCommerce plugin to version 1.0.43 or later.
Which versions of the Flexible Refund and Return Order for WooCommerce are affected by CVE-2025-12621?
CVE-2025-12621 affects all versions of the Flexible Refund and Return Order for WooCommerce plugin up to and including version 1.0.42.
What type of attack can exploit CVE-2025-12621?
CVE-2025-12621 can be exploited by authenticated users to perform unauthorized modifications to refund data.
What is the impact of CVE-2025-12621 on WooCommerce websites?
CVE-2025-12621 can lead to a significant compromise of refund integrity on WooCommerce websites, allowing attackers to manipulate refund processes.