Webkul · Bagisto · CVE-2026-75081
**Name of the Vulnerable Software and Affected Versions**
Webkul Bagisto versions prior to 2.4.5
**Description**
A remote issue exists in the `/customer/account/rma/store` file. Manipulation of the `rma qty`, `resolution type`, or `rma reason id` arguments allows for the enforcement of a behavioral workflow.
**Recommendations**
Update Webkul Bagisto to version 2.4.5 or later.
As a temporary mitigation, restrict access to the `/customer/account/rma/store` endpoint.