WC Return products
WC Return products has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for WC Return products has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nguyen Xuan Chien. WC Return products is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.7.35.
CVE-2025-59004WC Return products <= 1.5 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

WC Return products
Author
pco_58
This plugin allows you to add a form that send email with the product that user want’s to return when an order is placed in woocommerce. You can set user email, and how many days will be active this form in a order. You can specify order statuses for the WC Return form will be available. Filter for return button: ‘wc_return_order_button’ Filter for return form: ‘wc_return_order_form’ Action before send email: ‘wc_before_send_email’ If you find a bug or want to make an upgrade fill free to do it at GitHub
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C