Sensitive Data Exposure in WooCommerce Plugin by WordPress
CVE-2024-13641
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 February 2025
What is CVE-2024-13641?
The Return Refund and Exchange For WooCommerce plugin, compatible with WordPress, exposes sensitive information due to improper handling of file permissions. This vulnerability affects all versions up to and including 4.4.5, allowing unauthenticated attackers to access and extract sensitive data stored in the /wp-content/attachment directory. This includes potentially sensitive file attachments related to order refunds, making it crucial for users to update their plugin to ensure data security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Return Refund and Exchange For WooCommerce β Return Management System, RMA Exchange, Wallet And Cancel Order Features * <= 4.4.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved