CVE-2025-12086 | WPSwings Return Refund and Exchange for WooCommerce Plugin up to 4.5.5 on WordPress AJAX Endpoint wps_rma_cancel_return_request resource injection
A vulnerability labeled as problematic has been found in WPSwings Return Refund and Exchange for WooCommerce Plugin up to 4.5.5 on WordPress. Impacted is the function wps_rma_cancel_return_request of the component AJAX Endpoint. Such manipulation leads to improper control of resource identifiers.
This vulnerability is referenced as CVE-2025-12086. It is possible to launch the attack remotely. No exploit is available.