Unauthorized Data Modification Vulnerability in WiseCampaign Plugin for WordPress
CVE-2026-7529

7.5HIGH

What is CVE-2026-7529?

The WiseCampaign plugin for WordPress presents a serious security flaw where all its REST API endpoints are configured without proper permission checks. This oversight allows unauthorized individuals to manipulate critical settings within the plugin. Attackers can alter banners, update stockbar features, and upload images without any authentication or capability validation. The vulnerability impacts all versions up to and including 1.1.16, making it imperative for users to update and secure their installations to prevent potential exploitation.

Affected Version(s)

wiseCampaign – WooCommerce Con Made Easy 0 <= 1.1.16

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Legion Hunter
.