Description
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 via several functions due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite linked refund image attachments, overwrite refund request message, overwrite order messages, and read order messages of other users.
INFO
Published Date :
2025-02-14T05:22:44.354Z
Last Modified :
2026-04-08T17:27:26.757Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2024-13692 vulnerability.
| Vendors | Products |
|---|---|
| Wpswings |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-13692.