What the vulnerability does
01Description
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the 'attachment' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/attachment directory which can contain file attachments for order refunds.
Explanation of Vulnerability in Simple Terms
02Summary
The Return Refund and Exchange For WooCommerce plugin through version 4.4.5 exposes sensitive information to unauthenticated attackers over the network. The vulnerability requires specific conditions to exploit but does not require user interaction. Affected sites should update to a version newer than 4.4.5 to prevent unauthorized access to protected data.
What an attacker can do
03Attacker Capabilities
Read sensitive information without authentication, such as refund or exchange request details.
Potential impact on your site
04Site Impact
Customer refund and exchange data may be exposed to anyone on the internet without needing a login.
Conditions required to exploit
05Prerequisites
Network access; specific conditions must be met but no authentication or user interaction required.
Key dates
06Disclosure timeline
February 14, 2025
CVE published
April 8, 2026
Record updated