CyberRota Analysis
AI-GeneratedThe vulnerability affects WooCommerce versions up to 4.6.4, allowing unauthenticated users to exploit broken access control mechanisms related to return and exchange functionalities. This could lead to unauthorized access and manipulation of refund processes, potentially resulting in financial loss for businesses. Organizations using affected versions of WooCommerce should prioritize patching to mitigate the risk of exploitation.
CVE
CVE-2026-81799
Severity
HIGH
CVSS
7.5
EPSS
0.22%
Exchange
Original NVD Description
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.