HIGHCVSS 7.5Vulnerability
CVE-2026-7529
The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This makes it possible for unauthenticated attackers to read and modify the plugin's banner, stockbar, and core settings — including saving/updating banner records, toggling stockbar/feature flags, changing the active banner, and uploading background-image files via wp_handle_upload() — without any nonce or capability check.
Properties
- severity
- HIGH
- cvss_score
- 7.5
- cvss_severity
- HIGH
- epss_score
- 0.00626
- retrieved_at
- 2026-10-01T23:15:04+00:00
- last_source
- FIRST EPSS
- score
- 7.5
- cve_id
- CVE-2026-7529
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- signal_observed_at
- 2026-09-11T17:55:57+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- published_at
- 2026-08-05T14:17:15.237
- last_modified
- 2026-08-12T21:00:37.147
- epss_percentile
- 0.48103
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Missing Authorization
Explore deeper with Ninja Signal's threat intelligence graph