CyberRota Analysis
AI-GeneratedThe Return Refund and Exchange For WooCommerce plugin for WordPress prior to version 4.6.4 is vulnerable due to improper verification of guest order ownership, enabling unauthenticated users to access private order messages, post messages and attachments as if they were the customer, and cancel return requests on any guest order. This could lead to unauthorized access to sensitive customer information and manipulation of order processes. E-commerce platforms utilizing this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return requests on any guest order.