wiseCampaign <= 1.1.16 - Missing Authorization to Unauthenticated Plugin Configuration Modification via REST API
highThe wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This makes it possible for u...
- CVSS:
- 7.5
- Affected:
- up to 1.1.16
- Fixed in:
- 1.1.17
- Disclosed:
- Aug 4, 2026