Impact
The vulnerability allows any user to exploit WordPress REST API endpoints that were incorrectly registered with a permission callback that always returns true. This flaw lets an attacker read and alter the wiseCampaign plugin’s configuration, including banner and stockbar settings, active banner selection, and uploaded background images, without any authentication or nonce verification. The impact is unauthorized data modification and potential misuse of uploaded media, leading to loss of confidentiality, integrity, and availability of marketing assets and site appearance.
Affected Systems
The wiseCampaign – WooCommerce Conversions Made Easy WordPress plugin, any installation using version 1.1.16 or earlier, is affected. Vendors and site operators that rely on this plugin for banner, stockbar, or conversion tracking should be aware that their site configuration is exposed to unauthenticated users.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the vulnerability is exploitable with no authentication required. Because the endpoints are globally accessible, an attacker only needs to send crafted REST API requests, and there are no reported external exploits (EPSS not available) and the issue is not listed in CISA’s KEV catalog. The risk remains high due to the broad attack surface and the ease of exploitation.
OpenCVE Enrichment