WordPress Plugin Vulnerabilities

PixelYourSite < 11.2.2 and PixelYourSite PRO < 12.6.1 - Unauthenticated Sensitive Information Exposure via Order-Received Endpoint

Description

The plugins are vulnerable to Sensitive Information Exposure via the getWooPurchaseEventParams. This makes it possible for unauthenticated attackers to extract WooCommerce purchase metadata — including product names, product IDs, quantities, per-item prices, order totals, currency, and order/transaction IDs — for any existing order by supplying an invalid or arbitrary order key. This is exploitable against any known or enumerated order ID, as the plugins resolve the order from the URL path variable alone and emit the full woo_purchase tracking payload into the page HTML via the pysOptions JavaScript object across their Facebook, Google Analytics, and Google Tag Manager integrations regardless of key validity.

Affects Plugins

Fixed in 12.6.1
Fixed in 11.2.2

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Win3
Verified
No

Timeline

Publicly Published
2026-07-31 (about 24 days ago)
Added
2026-07-31 (about 23 days ago)
Last Updated
2026-07-31 (about 23 days ago)

Other