CVE-2026-77695: Woo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and Manipulation
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return requests on any guest order.
Affected Software
Event History
Frequently Asked Questions
Which stores are exposed to this issue?
Stores using Woo Refund And Exchange Lite versions earlier than 4.6.4 are affected where guest orders are present. The issue concerns AJAX actions available to unauthenticated users.
Does an attacker need an account or authenticated access?
No. The affected actions can be reached by unauthenticated users, and the flaw is the plugin's failure to correctly verify ownership of some guest orders.
What could an attacker do to an affected guest order?
An attacker could read private order messages, submit messages and attachments in the customer's name, and cancel return requests for guest orders.