PT-2026-68173 · WordPress · Wisecampaign

·

CVE-2026-7529

·

Published

2026-08-05

·

Updated

2026-08-05

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions wiseCampaign – WooCommerce Conversions Made Easy versions prior to 1.1.17
Description The plugin is susceptible to unauthorized data disclosure and modification because all REST API endpoints are registered with permission callback => ' return true', which bypasses necessary authorization. This allows unauthenticated attackers to read and modify core settings, stockbar configurations, and banner records. Additionally, attackers can toggle feature flags, change the active banner, and upload background-image files using the wp handle upload() function without providing a nonce or passing a capability check.
Recommendations Update the plugin to a version later than 1.1.16.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7529

Affected Products

Wisecampaign