Arbitrary File Upload Vulnerability in WooCommerce Refund And Exchange by WordPress
CVE-2025-6222
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 18 July 2025
What is CVE-2025-6222?
The WooCommerce Refund And Exchange with RMA theme for WordPress is susceptible to an arbitrary file upload vulnerability due to inadequate file type validation in the 'ced_rnx_order_exchange_attach_files' function. This flaw allows unauthenticated attackers to potentially upload malicious files to the server, which could facilitate remote code execution, compromising the security of the affected site. All versions up to and including 3.2.6 are impacted.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet * <= 3.2.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved