SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-81799

HIGH · CVSS 7.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability affects WooCommerce versions up to 4.6.4, allowing unauthenticated users to exploit broken access control mechanisms related to return and exchange functionalities. This could lead to unauthorized access and manipulation of refund processes, potentially resulting in financial loss for businesses. Organizations using affected versions of WooCommerce should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-81799
Severity
HIGH
CVSS
7.5
EPSS
0.22%
Exchange

Original NVD Description

Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.