Unauthorized Data Modification in Reviso Exporter for WooCommerce Plugin by WordPress
CVE-2026-8615
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-8615?
The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized data modification due to a lack of capability checks and nonce verifications in the disconnect_callback() function. This function, linked to the 'wp_ajax_wcefr-disconnect' AJAX action, can be exploited by authenticated users with Subscriber-level access or higher. The vulnerability allows these attackers to delete the Agreement Grant Token by invoking delete_option('wcefr-agt'), which effectively severs the connection between WooCommerce and the Reviso API. The absence of proper verification mechanisms poses a significant risk for data integrity within the affected plugin.
Affected Version(s)
ilGhera Reviso Exporter for WooCommerce 0 <= 1.2.3