Insecure Direct Object Reference in WooCommerce Return Refund and Exchange Plugin by WordPress
CVE-2025-12881
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 November 2025
What is CVE-2025-12881?
The Return Refund and Exchange For WooCommerce plugin allows authenticated users with at least Subscriber-level access to exploit an Insecure Direct Object Reference vulnerability. This occurs through the wps_rma_fetch_order_msgs() function, where missing validation on a user-controlled key enables attackers to access and read order messages belonging to other users, potentially leading to unauthorized information disclosure. All versions up to and including 4.5.5 are impacted.
Affected Version(s)
Return Refund and Exchange For WooCommerce 0 <= 4.5.5