Executive brief
The Revive.so plugin for WordPress, used for social media automation and content resharing, contains a security flaw in its access control system. This vulnerability allows unauthorized individuals to bypass intended security levels and potentially perform actions or modify settings they should not have access to. While the immediate risk is considered medium, it could allow attackers to interfere with the plugin's operations or site configuration.
Technical details
A missing authorization vulnerability (CWE-862) exists in the WP Chill Revive.so plugin for WordPress in versions up to and including 2.0.7. The flaw stems from a failure to properly validate user permissions or implement sufficient access control checks on specific functions. An unauthenticated remote attacker can exploit this to execute actions or access functionality that should be restricted to higher-privileged users. The vulnerability is addressed in version 2.0.8, which introduces proper authorization checks.
Affected products
- WP Chill Revive.so (revive-so) <= 2.0.7
Timeline
- 2026-02-10: other: Reported by Muhammad Sharief
- 2026-03-12: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published
- 2026-03-12: patched: Fixed in version 2.0.8