Impact
The Reviso Exporter for WooCommerce plugin allows an authenticated user to invoke the wp_ajax_wcefr‑disconnect AJAX action, which unconditionally deletes the database option holding the Reviso Agreement Grant Token. Because the code lacks both a capability check and nonce verification, any user with Subscriber or higher privileges can trigger this deletion. The effect is loss of the authenticated link between WooCommerce and the external Reviso service, potentially disrupting automated reconciliation and reporting that rely on that connection. The weakness is an authorization bypass, identified as CWE‑862.
Affected Systems
Any WordPress installation running the Reviso Exporter for WooCommerce plugin version 1.2.3 or earlier is vulnerable. The issue is limited to the plugin’s handler for the wp_ajax_wcefr‑disconnect action and does not affect other parts of WordPress core or unrelated plugins.
Risk and Exploitability
The likely attack vector is internal; the attacker needs only legitimate WordPress credentials with Subscriber or higher access to trigger the disconnection. The CVSS score of 4.3 reflects a moderate severity driven by the narrow scope of the exploit, as the vulnerability only affects the plugin’s disconnect functionality. The vulnerability is not listed in CISA KEV and no EPSS data is available, indicating that it is not widely reported as actively exploited. However, because the delete operation can be invoked with minimal effort and the exploit requires only an authenticated role, the likelihood of exploitation on multitenant e‑commerce sites where compromised credentials are common is comparatively high.
OpenCVE Enrichment