CVE-2026-57402
Deferred Deferred - Pending Action

Stored XSS in Flexible Refund and Return Order for WooCommerce

Vulnerability report for CVE-2026-57402, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-13

Assigner: Patchstack

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Refund and Return Order for WooCommerce flexible-refund-and-return-order-for-woocommerce allows Stored XSS.This issue affects Flexible Refund and Return Order for WooCommerce: from n/a through <= 1.0.51.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-13
Generated
2026-08-02
AI Q&A
2026-07-13
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wpdesk flexible_refund_and_return_order_for_woocommerce to 1.0.51 (inc)
wpdesk flexible_refund_and_return_order_for_woocommerce From 1.0.0 (inc) to 1.0.51 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-57402 is a Cross Site Scripting (XSS) vulnerability found in the WordPress Flexible Refund and Return Order for WooCommerce Plugin, versions 1.0.51 and below.

This vulnerability occurs due to improper neutralization of input during web page generation, allowing attackers to inject malicious scripts into the website.

These malicious scripts can execute harmful payloads such as redirects or unwanted advertisements when visitors access the affected site.

Exploitation requires a privileged user to perform an action like clicking a malicious link or submitting a form.

Detection Guidance

This vulnerability involves stored Cross-Site Scripting (XSS) in the WordPress Flexible Refund and Return Order for WooCommerce plugin versions 1.0.51 and below. Detection typically involves identifying malicious script injections in web pages generated by the plugin.

While no specific commands are provided in the resources, common detection methods include scanning the affected web pages or database entries for suspicious script tags or payloads that could indicate stored XSS.

Additionally, monitoring web traffic for unusual redirects or unexpected script execution when accessing pages related to the plugin may help detect exploitation attempts.

Impact Analysis

This vulnerability can lead to attackers injecting malicious scripts that execute harmful actions on your website, such as redirecting visitors to malicious sites or displaying unwanted advertisements.

Because the vulnerability requires a privileged user to interact with a malicious element, it poses a moderate risk but can be exploited in large-scale attacks targeting many websites.

Successful exploitation can compromise the integrity and trustworthiness of your website, potentially harming your users and your reputation.

Compliance Impact

This vulnerability, a stored Cross-Site Scripting (XSS) flaw, can impact compliance with standards and regulations like GDPR and HIPAA due to its potential to compromise data integrity and confidentiality.

  • GDPR: The vulnerability allows attackers to inject malicious scripts that could steal sensitive user data, such as personal information or session cookies. This violates GDPR's requirements for protecting personal data (Article 5) and ensuring appropriate security measures (Article 32). A successful exploit could lead to unauthorized access to personal data, triggering mandatory breach notifications (Article 33) and potential fines.
  • HIPAA: If the affected WooCommerce plugin is used in a healthcare-related context (e.g., processing refunds for medical services), the vulnerability could expose protected health information (PHI). HIPAA requires safeguards to ensure the confidentiality, integrity, and availability of PHI (Security Rule). An XSS exploit could lead to unauthorized access or disclosure of PHI, resulting in non-compliance and potential penalties.

Additionally, the vulnerability's requirement for a privileged user to interact with malicious content (e.g., clicking a link) does not eliminate compliance risks, as attackers could target administrators or users with elevated access to escalate the impact.

Mitigation Strategies

The immediate mitigation step is to update the Flexible Refund and Return Order for WooCommerce plugin to version 1.0.52 or later, where the vulnerability is patched.

Until the update can be applied, it is recommended to implement the mitigation rule provided by Patchstack to block attacks targeting this vulnerability.

Since the vulnerability requires a privileged user action, restricting user privileges and educating users about the risks of clicking suspicious links or submitting untrusted forms can also reduce risk.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57402. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart