ilGhera Reviso Exporter for WooCommerce
ilGhera Reviso Exporter for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for ilGhera Reviso Exporter for WooCommerce has a vendor fix available, so running the current release closes it.
All of these findings were reported by Legion Hunter. ilGhera Reviso Exporter for WooCommerce is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-8615ilGhera Reviso Exporter for WooCommerce <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function
Read the full analysisVulnerability Records

ilGhera Reviso Exporter for WooCommerce
Author
ilGhera
Export suppliers, products, customers and orders from your Woocommerce store to Reviso. Export new orders and create invoices in real time. AVAILABLE FEATURES Export WordPress users to Reviso. Select one or more WordPress user level to export. Update customers and suppliers in Reviso in real time (Premium). Export products to Reviso. Select one or more product categories to export. Update products in Reviso in real time (Premium). Export orders to Reviso. Export new orders to Reviso in real time (Premium). Create invoices in Reviso with completed orders (Premium). Send PDF invoice to the customer attached to the order’s email (Premium). Add specific fields for electronic invoicing to the checkout form. Delete all data in Reviso with a click. Try Reviso for free! https://www.reviso.com/trial?src=hero IMPORTANT NOTES This plugin sends data to an external service, like the products bought by the user and profile informations. Service informations: https://www.reviso.com/ Service endpoint: https://rest.reviso.com/ Service privacy policy: https://www.reviso.com/privacy-policy-en
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C