Description
The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the disconnect_callback() function in versions up to, and including, 1.2.3. The function is registered to the 'wp_ajax_wcefr-disconnect' AJAX action and unconditionally calls delete_option('wcefr-agt'), which removes the Reviso Agreement Grant Token used to authenticate API calls. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's stored Agreement Grant Token, breaking the connection between WooCommerce and the Reviso service.
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized deletion of the Reviso Agreement Grant Token by any authenticated user with Subscriber-level access or higher
Action: Patch promptly
AI Analysis

Impact

The Reviso Exporter for WooCommerce plugin allows an authenticated user to invoke the wp_ajax_wcefr‑disconnect AJAX action, which unconditionally deletes the database option holding the Reviso Agreement Grant Token. Because the code lacks both a capability check and nonce verification, any user with Subscriber or higher privileges can trigger this deletion. The effect is loss of the authenticated link between WooCommerce and the external Reviso service, potentially disrupting automated reconciliation and reporting that rely on that connection. The weakness is an authorization bypass, identified as CWE‑862.

Affected Systems

Any WordPress installation running the Reviso Exporter for WooCommerce plugin version 1.2.3 or earlier is vulnerable. The issue is limited to the plugin’s handler for the wp_ajax_wcefr‑disconnect action and does not affect other parts of WordPress core or unrelated plugins.

Risk and Exploitability

The likely attack vector is internal; the attacker needs only legitimate WordPress credentials with Subscriber or higher access to trigger the disconnection. The CVSS score of 4.3 reflects a moderate severity driven by the narrow scope of the exploit, as the vulnerability only affects the plugin’s disconnect functionality. The vulnerability is not listed in CISA KEV and no EPSS data is available, indicating that it is not widely reported as actively exploited. However, because the delete operation can be invoked with minimal effort and the exploit requires only an authenticated role, the likelihood of exploitation on multitenant e‑commerce sites where compromised credentials are common is comparatively high.

Generated by OpenCVE AI on September 9, 2026 at 11:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Reviso Exporter for WooCommerce plugin to the latest release that includes the missing capability check and nonce verification for the disconnect action; if no newer version exists, uninstall the plugin to eliminate the vulnerability.
  • Add custom code or use a security plugin to restrict access to the wp_ajax_wcefr‑disconnect AJAX action, ensuring a capability check and nonce validation are performed or that the endpoint is blocked for non‑administrator roles.
  • Monitor the database for the presence of the 'wcefr-agt' option and investigate any unexpected deletions to confirm the effectiveness of the applied controls.

Generated by OpenCVE AI on September 9, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ghera74
Ghera74 ilghera Support System For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Ghera74
Ghera74 ilghera Support System For Woocommerce
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the disconnect_callback() function in versions up to, and including, 1.2.3. The function is registered to the 'wp_ajax_wcefr-disconnect' AJAX action and unconditionally calls delete_option('wcefr-agt'), which removes the Reviso Agreement Grant Token used to authenticate API calls. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's stored Agreement Grant Token, breaking the connection between WooCommerce and the Reviso service.
Title ilGhera Reviso Exporter for WooCommerce <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Ghera74 Ilghera Support System For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T20:19:14.384Z

Reserved: 2026-05-14T17:36:38.095Z

Link: CVE-2026-8615

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:18.693

Modified: 2026-09-11T21:17:58.670

Link: CVE-2026-8615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:05Z

Weaknesses