Flexible Refund for WooCommerce – EU One Click Return <= 1.0.51 - Authenticated (Customer+) Stored Cross-Site Scripting
medium
The Flexible Refund for WooCommerce – EU One Click Return plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.51 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with customer-level access and above, to in...
- CVSS:
- 6.4
- Affected:
- up to 1.0.51
- Fixed in:
- 1.0.52
- Disclosed:
- Jul 8, 2026
CVE-2026-57402 on NVD →
Flexible Refund and Return Order for WooCommerce <= 1.0.42 - Incorrect Authorization to Authenticated (Contributor+) Refund Status Update
medium
The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'create_refund' function in all versions up to, and including, 1.0.42. This makes it possible for authenticated attackers, with Contributor-level ac...
- CVSS:
- 5.3
- Affected:
- up to 1.0.42
- Fixed in:
- 1.0.43
- Disclosed:
- Nov 7, 2025
CVE-2025-12621 on NVD →
Flexible Refund and Return Order for WooCommerce <= 1.0.38 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Refund
medium
The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.38 via the save_refund_request() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to submit refund requests for...
- CVSS:
- 4.3
- Affected:
- up to 1.0.38
- Fixed in:
- 1.0.39
- Disclosed:
- Oct 21, 2025
CVE-2025-10570 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database