PT-2026-68173 · WordPress · Wisecampaign
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
wiseCampaign – WooCommerce Conversions Made Easy versions prior to 1.1.17
Description
The plugin is susceptible to unauthorized data disclosure and modification because all REST API endpoints are registered with
permission callback => ' return true', which bypasses necessary authorization. This allows unauthenticated attackers to read and modify core settings, stockbar configurations, and banner records. Additionally, attackers can toggle feature flags, change the active banner, and upload background-image files using the wp handle upload() function without providing a nonce or passing a capability check.Recommendations
Update the plugin to a version later than 1.1.16.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wisecampaign