CVE-2026-8615

Source
https://cve.org/CVERecord?id=CVE-2026-8615
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8615.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-8615
Published
2026-09-09T05:31:05Z
Modified
2026-09-13T03:30:44Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
ilGhera Reviso Exporter for WooCommerce <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function
Details

The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the disconnect_callback() function in versions up to, and including, 1.2.3. The function is registered to the 'wp_ajax_wcefr-disconnect' AJAX action and unconditionally calls delete_option('wcefr-agt'), which removes the Reviso Agreement Grant Token used to authenticate API calls. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's stored Agreement Grant Token, breaking the connection between WooCommerce and the Reviso service.

Database specific
{
    "cna_assigner": "Wordfence",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8615.json"
}
References

Affected packages

Git / github.com/ilghera/wc-exporter-for-reviso

Affected ranges

Type
GIT
Repo
https://github.com/ilghera/wc-exporter-for-reviso
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.2.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

free-0.*
free-0.9.0
free-0.9.1
free-0.9.2
free-0.9.3
free-0.9.4
free-0.9.5
free-0.9.6
free-1.*
free-1.0.0
free-1.1.0
free-1.2.0
free-1.2.1
free-1.2.2
free-1.2.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8615.json"