← WordPress Vulnerabilities
WordPress security by component

Pixel Tag Manager for WooCommerce

Pixel Tag Manager for WooCommerce is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: pixel-tag-manager-for-woocommerce

CVE-2026-14315: Pixel Tag Manager lets visitors forge server-side advertising conversions

Pixel Tag Manager for WooCommerce before 2.2.1 exposes an AJAX action without an authorization check. An unauthenticated visitor can submit attacker-controlled e-commerce conversion data, which the plugin forwards to configured server-side advertising conversion APIs using credentials stored by the site owner. The record does not disclose the AJAX action, event parameters, callback or external API methods.

PublishedAug 01, 2026
Known safe version2.2.1
Safe version
Aug 01, 2026 CVE-2026-14315
Pixel Tag Manager lets visitors forge server-side advertising conversions
Pixel Tag Manager for WooCommerce before 2.2.1 exposes an AJAX action without an authorization check. An unauthenticated visitor can submit attacker-controlled e-commerce conversion data, which the plugin forwards to configured server-side advertising conversion APIs using credentials stored by the site owner. The record does not disclose the AJAX action, event parameters, callback or external API methods.
2.2.1
CVEPending
NVDPending