CVE-2025-12621: Wpdesk Flexible Refund And Return Order For Woocommerce

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'create_refund' function in all versions up to, and including, 1.0.42. This makes it possible for authenticated attackers, with Contributor-level access and above, to update the status of refund requests, including approving and refusing refunds.

Affected products

  • Wpdesk Flexible Refund And Return Order For Woocommerce: up to and including 1.0.42

Published 2025-11-08. Last modified 2026-10-07.