Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-8615— ilGhera Reviso Exporter for WooCommerce <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function

Quick assessment

Affected
ghera74 ilGhera Reviso Exporter for WooCommerce
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Reviso Exporter for WooCommerce 插件存在未授权数据修改漏洞,原因是 函数缺少权限检查和 nonce 验证,该漏洞影响版本 1.2.3 及之前版本。 该函数被注册为 AJAX 操作,并会无条件调用 ,从而删除用于身份验证 API 调用的 Reviso 协议授权令牌(Agreement Grant Token)。 这使得拥有订阅者(Subscriber)级别及以上权限的已认证攻击者能够删除插件存储的协议授权令牌,进而破坏 WooCommerce 与 Reviso

CVSS 4.3 · Medium

Possible ATT&CK Techniques 1 AI

T1079
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-8615

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ilGhera Reviso Exporter for WooCommerce <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function
Source: CVE Program / CVE List V5
Vulnerability Description
The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the disconnect_callback() function in versions up to, and including, 1.2.3. The function is registered to the 'wp_ajax_wcefr-disconnect' AJAX action and unconditionally calls delete_option('wcefr-agt'), which removes the Reviso Agreement Grant Token used to authenticate API calls. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's stored Agreement Grant Token, breaking the connection between WooCommerce and the Reviso service.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ghera74 ilGhera Reviso Exporter for WooCommerce 0 ~ 1.2.3 -

II. Public POCs for CVE-2026-8615

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-8615

登录查看更多情报信息。

Other References for CVE-2026-8615 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-8615

No comments yet


Leave a comment