Description

Authorization Bypass Through User-Controlled Key vulnerability in YoOhw Studio Order Cancellation &amp; Returns for WooCommerce wc-order-cancellation-return allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Cancellation &amp; Returns for WooCommerce: from n/a through <= 1.1.11.

INFO

Published Date :

2025-12-31T16:25:44.989Z

Last Modified :

2026-04-01T15:55:24.391Z

Source :

Patchstack
AFFECTED PRODUCTS

The following products are affected by CVE-2025-49352 vulnerability.

Vendors Products
Woocommerce
  • Woocommerce
Wordpress
  • Wordpress
Yoohw Studio
  • Order Cancellation & Returns For Woocommerce

CVSS Vulnerability Scoring System