Description
The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This makes it possible for unauthenticated attackers to read and modify the plugin's banner, stockbar, and core settings — including saving/updating banner records, toggling stockbar/feature flags, changing the active banner, and uploading background-image files via wp_handle_upload() — without any nonce or capability check.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows any user to exploit WordPress REST API endpoints that were incorrectly registered with a permission callback that always returns true. This flaw lets an attacker read and alter the wiseCampaign plugin’s configuration, including banner and stockbar settings, active banner selection, and uploaded background images, without any authentication or nonce verification. The impact is unauthorized data modification and potential misuse of uploaded media, leading to loss of confidentiality, integrity, and availability of marketing assets and site appearance.

Affected Systems

The wiseCampaign – WooCommerce Conversions Made Easy WordPress plugin, any installation using version 1.1.16 or earlier, is affected. Vendors and site operators that rely on this plugin for banner, stockbar, or conversion tracking should be aware that their site configuration is exposed to unauthenticated users.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, and the vulnerability is exploitable with no authentication required. Because the endpoints are globally accessible, an attacker only needs to send crafted REST API requests, and there are no reported external exploits (EPSS not available) and the issue is not listed in CISA’s KEV catalog. The risk remains high due to the broad attack surface and the ease of exploitation.

Generated by OpenCVE AI on August 5, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the wiseCampaign plugin to the latest available version that removes the insecure permission callbacks
  • If an immediate update is not possible, disable or restrict the plugin’s REST API endpoints from non‑privileged users by adding custom permission callbacks or removing the routes entirely
  • Apply a general WordPress security best practice: enforce role‑based access control and routine patch management for all plugins

Generated by OpenCVE AI on August 5, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wisemattic
Wisemattic wisecampaign – Woocommerce Conversions Made Easy
Wordpress
Wordpress wordpress
Vendors & Products Wisemattic
Wisemattic wisecampaign – Woocommerce Conversions Made Easy
Wordpress
Wordpress wordpress

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This makes it possible for unauthenticated attackers to read and modify the plugin's banner, stockbar, and core settings — including saving/updating banner records, toggling stockbar/feature flags, changing the active banner, and uploading background-image files via wp_handle_upload() — without any nonce or capability check.
Title wiseCampaign <= 1.1.16 - Missing Authorization to Unauthenticated Plugin Configuration Modification via REST API
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Wisemattic Wisecampaign – Woocommerce Conversions Made Easy
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-05T14:43:46.036Z

Reserved: 2026-04-30T17:45:09.114Z

Link: CVE-2026-7529

cve-icon Vulnrichment

Updated: 2026-08-05T14:43:40.312Z

cve-icon NVD

Status : Deferred

Published: 2026-08-05T14:17:15.237

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-7529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:06:30Z

Weaknesses