CVE-2026-81799
Deferred Deferred - Pending Action

Unauthenticated Broken Access Control in Return Refund and Exchange for WooCommerce

Vulnerability report for CVE-2026-81799, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Patchstack

Description

Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
patchstack return_refund_and_exchange_for_woocommerce to 4.6.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated broken access control vulnerability in the Return Refund and Exchange For WooCommerce plugin versions 4.6.4 and below. It allows attackers to perform privileged actions without authentication due to missing authorization checks.

Detection Guidance

Since this is a WordPress plugin vulnerability, check if the Return Refund and Exchange For WooCommerce plugin version 4.6.4 or below is installed. Inspect server logs for unusual privileged actions or unauthorized refund/exchange requests. No specific commands are provided in the context.

Impact Analysis

Unauthenticated attackers can exploit this to perform privileged actions on vulnerable websites. This may lead to unauthorized refunds, exchanges, or other administrative changes without proper authorization.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves unauthorized access control in a WordPress plugin. However, if exploited, it could lead to unauthorized refunds or exchanges, potentially violating data integrity or financial transaction records, which may indirectly impact compliance depending on how the plugin is used in a system handling sensitive data.

Mitigation Strategies

Apply the Patchstack mitigation rule to block attacks until an official patch is released. Consider updating the plugin or contacting your hosting provider or developer for assistance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81799. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart