WordPress Plugin Vulnerabilities

Pixel Tag Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission

Description

The plugin does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials.

Proof of Concept

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-07-20 (about 1 month ago)
Added
2026-07-20 (about 1 month ago)
Last Updated
2026-08-12 (about 1 month ago)

Other