vulnerability
WordPress Plugin: flexible-refund-and-return-order-for-woocommerce: CVE-2025-10570: Authorization Bypass Through User-Controlled Key
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:L/Au:S/C:N/I:P/A:N) | Oct 21, 2025 | Oct 22, 2025 | Oct 23, 2025 |
Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:N)
Published
Oct 21, 2025
Added
Oct 22, 2025
Modified
Oct 23, 2025
Description
The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.38 via the save_refund_request() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to submit refund requests for arbitrary orders that they do not own.
Solution
flexible-refund-and-return-order-for-woocommerce-plugin-cve-2025-10570
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.