Access violation vulnerability in Flexible Refund and Return Order for WooCommerce 1.0.38

The plugin called “Flexible Refund and Return Order” for WordPress can be easily hacked. This vulnerability affects all versions up to 1.0.38 and is caused by a function called “save_refund_request()”. This means that someone who has logged in and has at least subscriber-level access can request a refund for any order, even if they didn’t make the purchase.

Detected in:

Flexible Refund and Return Order for WooCommerce fixed vulnerable versions: >= * <= 1.0.38

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.