Wpswings
Wpswings Return Refund AND Exchange FOR Woocommerce: vulnerabilidades y CVE
Wpswings Return Refund AND Exchange FOR Woocommerce tiene 7 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81799 | Alta (7.5) | 0.35% | — | 10 sept 2026 | Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions. |
| CVE-2026-77695 | Media (6.5) | 0.27% | — | 26 ago 2026 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read… |
| CVE-2025-12881 | Media (5.4) | 0.17% | — | 21 nov 2025 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the wps_rma_fetch_order_msgs() due to missing… |
| CVE-2025-12086 | Media (4.3) | 0.19% | — | 21 nov 2025 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the 'wps_rma_cancel_return_request' AJAX endpoint due… |
| CVE-2024-13692 | Media (5.4) | 0.31% | — | 14 feb 2025 | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and… |
| CVE-2024-13641 | Alta (7.5) | 0.47% | — | 14 feb 2025 | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… |
| CVE-2022-4047 | Crítica (9.8) | 6.2% | — | 26 dic 2022 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Wpswings
Wallet System FOR Woocommerce · 11Membership FOR Woocommerce · 7Ultimate Gift Cards FOR Woocommerce · 6Points AND Rewards FOR Woocommerce · 4Woocommerce Ultimate Gift Card · 3PDF Generator FOR Wordpress · 2Subscriptions FOR Woocommerce · 2Coupon Referral Program · 2Woocommerce Ultimate Points AND Rewards · 1Event Tickets Manager FOR Woocommerce · 1Gift Cards FOR Woocommerce PRO · 1Mautic Integration FOR Woocommerce · 1