CVE-2026-81799: WordPress Return Refund and Exchange For WooCommerce plugin <= 4.6.4 - Broken Access Control vulnerability
Published Sep 10, 2026
·Updated
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
Affected Software
1 affected component
WordPress Return Refund and Exchange For WooCommerce<=4.6.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Return Refund and Exchange For WooCommerce pluginto a version that resolves this vulnerability.Fixed in 4.6.4
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or WooCommerce credentials to exploit it.
2
Which plugin versions are affected?
Return Refund and Exchange For WooCommerce versions 4.6.4 and earlier are affected.
3
What is the likely security impact?
The published vector rates impact as integrity-only and high severity (7.5), with no stated confidentiality or availability impact.