WordPress security by component
Pixel Tag Manager for WooCommerce
Plugin description
Pixel Tag Manager for WooCommerce is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
pixel-tag-manager-for-woocommerceLatest vulnerability
CVE-2026-14315: Pixel Tag Manager lets visitors forge server-side advertising conversions
Pixel Tag Manager for WooCommerce before 2.2.1 exposes an AJAX action without an authorization check. An unauthenticated visitor can submit attacker-controlled e-commerce conversion data, which the plugin forwards to configured server-side advertising conversion APIs using credentials stored by the site owner. The record does not disclose the AJAX action, event parameters, callback or external API methods.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-14315
Pixel Tag Manager lets visitors forge server-side advertising conversions
Pixel Tag Manager for WooCommerce before 2.2.1 exposes an AJAX action without an authorization check. An unauthenticated visitor can submit attacker-controlled e-commerce conversion data, which the plugin forwards to configured server-side advertising conversion APIs using credentials stored by the site owner. The record does not disclose the AJAX action, event parameters, callback or external API methods.
|
2.2.1 |
CVEPending
NVDPending
|