Extension WordPress
Vulnérabilités Flexible Refund for WooCommerce – EU One Click Return
Cette page rassemble les failles publiées pour Flexible Refund for WooCommerce – EU One Click Return, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Flexible Refund for WooCommerce – EU One Click Return
3 fiches
Flexible Refund for WooCommerce – EU One Click Return <= 1.0.51 – Authenticated (Customer+) Stored Cross-Site Scripting
The Flexible Refund for WooCommerce – EU One Click Return plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.51 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.0.51
1.0.52
08/07/2026
Flexible Refund and Return Order for WooCommerce <= 1.0.42 – Incorrect Authorization to Authenticated (Contributor+) Refund Status Update
The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'create_refund' function in all versions up to, and including, 1.0.42. This makes…
*-1.0.42
1.0.43
07/11/2025
Flexible Refund and Return Order for WooCommerce <= 1.0.38 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Refund
The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.38 via the save_refund_request() function. This makes it possible for authenticated attackers, with subscriber-level access…
*-1.0.38
1.0.39
21/10/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.