CVE-2025-12881: Return Refund and Exchange For WooCommerce <= 4.5.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Order Message Read
The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the wpsrmafetchordermsgs() due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read other user's order messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12881?
CVE-2025-12881 is classified as a high severity vulnerability due to the potential for unauthorized data access.
How do I fix CVE-2025-12881?
To fix CVE-2025-12881, update the Return Refund and Exchange For WooCommerce plugin to version 4.5.6 or later.
What is the impact of CVE-2025-12881?
The impact of CVE-2025-12881 allows attackers to access order messages without proper authorization.
Which versions of the Return Refund and Exchange For WooCommerce plugin are affected by CVE-2025-12881?
All versions of the Return Refund and Exchange For WooCommerce plugin up to and including 4.5.5 are affected by CVE-2025-12881.
Who is affected by CVE-2025-12881?
Users of the Return Refund and Exchange For WooCommerce plugin on WordPress who have not upgraded to version 4.5.6 or later are at risk from CVE-2025-12881.