Unauthorized Data Modification Vulnerability in WiseCampaign Plugin for WordPress
CVE-2026-7529
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-7529?
The WiseCampaign plugin for WordPress presents a serious security flaw where all its REST API endpoints are configured without proper permission checks. This oversight allows unauthorized individuals to manipulate critical settings within the plugin. Attackers can alter banners, update stockbar features, and upload images without any authentication or capability validation. The vulnerability impacts all versions up to and including 1.1.16, making it imperative for users to update and secure their installations to prevent potential exploitation.
Affected Version(s)
wiseCampaign β WooCommerce Con Made Easy 0 <= 1.1.16