CVE-2025-12086 | WPSwings Return Refund and Exchange for WooCommerce Plugin up to 4.5.5 on WordPress AJAX Endpoint wps_rma_cancel_return_request resource injection
A vulnerability was found in WPSwings Return Refund and Exchange for WooCommerce Plugin up to 4.5.5 on WordPress. It has been declared as problematic. Affected by this issue is the function wps_rma_cancel_return_request of the component AJAX Endpoint. Executing manipulation can lead to improper control of resource identifiers.
This vulnerability is handled as CVE-2025-12086. The attack can be executed remotely. There is not any exploit available.