HIGH
wisemattic
CVE published 2026-08-05
CVE-2026-7529
The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress has a vulnerability allowing unauthorized modification and disclosure of data due to its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This allows unauthenticated attackers to read and modify plugin settings, including banner records, stockbar flags, a [truncated]