The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return requests on any guest order.
We have discovered 460 live websites that are affected by CVE-2026-77695.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 460 live websites (92% of Woo Refund And Exchange Lite install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 16 versions ( 57% of all versions) |
| 151 websites | |
| 63 websites | |
| 29 websites | |
| 28 websites | |
| 24 websites | |
| 19 websites | |
| 16 websites | |
| 16 websites | |
| 13 websites | |
| 13 websites |
| .com | 292 websites |
| .it | 19 websites |
| .pl | 14 websites |
| .nl | 13 websites |
| .co.uk | 11 websites |
| .es | 7 websites |
| .com.au | 6 websites |
| .de | 6 websites |
| .at | 4 websites |
| .fr | 4 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | ***,*** | ||
| ******.com | ***,*** | ||
| **************.org | ***,*** | ||
| ******.com | ***,*** | ||
| *****.store | ***,*** | ||
| ****************.com | *,***,*** | ||
| *********.com | *,***,*** | ||
| ********.com | *,***,*** | ||
| ****************.com | *,***,*** | ||
| ******.com | *,***,*** |
FAQ