CVE-2026-81799
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- CWE
- CWE-862
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- WP Swings Return Refund and Exchange For WooCommerce
Weakness type
Related vulnerabilities
- CVE-2026-90454 — A deployment mode intended to expose only read access to a bundled packet-analysis component's...
- CVE-2026-90448 — A deployment mode intended to expose only read access to stored data proxies a set of application...
- CVE-2026-49439 — OpenRemote read-only asset users can write predicted datapoints
- CVE-2026-50025 — Mousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie state
- CVE-2026-68535 — Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path letting an editor reference files outside their file-manager permissions
- CVE-2026-81916 — Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object
- CVE-2026-81915 — In Concrete CMS below 9.5.3, Page Type update omits object-level authorization
- CVE-2026-62089 — WordPress Master Addons for Elementor plugin <= 3.2.2 - Broken Access Control vulnerability