Impact
The Reviewify plugin contains a missing capability check on the “send_test_email” AJAX action that allows any authenticated user with the Contributor role or higher to create arbitrary WooCommerce discount coupons. This flaw enables the attacker to generate coupons that apply undesired discounts, potentially resulting in direct financial loss for the store.
Affected Systems
The flaw affects Version 1.0.7 and all earlier releases of Reviewify by xfinitysoft, a WordPress plugin used to manage reviews and discount code integration with WooCommerce. Any WordPress installation that has a vulnerable Reviewify plugin and allows Contributor‑level users to log in is susceptible.
Risk and Exploitability
The vulnerability can be exploited through a normal web request to the AJAX endpoint that is otherwise protected by a missing capability check. Attackers need only an authenticated Contributor or higher account, which is commonly available on many sites. The CVSS score of 7.5 indicates a moderate to high severity, but the EPSS score of less than 1% signals a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. While the risk of a successful exploit is moderate, the potential impact on revenue makes it important to remediate promptly.
OpenCVE Enrichment