Unauthorized Data Modification in Flexible Refund Plugin for WooCommerce by WordPress
CVE-2025-12621
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 November 2025
What is CVE-2025-12621?
The Flexible Refund and Return Order for WooCommerce plugin for WordPress contains a vulnerability that arises from a misconfigured capability check in the 'create_refund' function. This issue permits authenticated attackers, including those with Contributor-level permissions and above, to modify refund request statuses. Attackers can approve or refuse refunds without proper authorization, leading to potential financial repercussions for online stores using this plugin.
Affected Version(s)
Flexible Refund and Return Order for WooCommerce * <= 1.0.42