WordPress Plugin Vulnerabilities
PixelYourSite < 11.2.2 and PixelYourSite PRO < 12.6.1 - Unauthenticated Sensitive Information Exposure via Order-Received Endpoint
Description
The plugins are vulnerable to Sensitive Information Exposure via the getWooPurchaseEventParams. This makes it possible for unauthenticated attackers to extract WooCommerce purchase metadata — including product names, product IDs, quantities, per-item prices, order totals, currency, and order/transaction IDs — for any existing order by supplying an invalid or arbitrary order key. This is exploitable against any known or enumerated order ID, as the plugins resolve the order from the URL path variable alone and emit the full woo_purchase tracking payload into the page HTML via the pysOptions JavaScript object across their Facebook, Google Analytics, and Google Tag Manager integrations regardless of key validity.
Affects Plugins
References
Classification
Type
SENSITIVE DATA DISCLOSURE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Win3
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-07-31 (about 24 days ago)
Added
2026-07-31 (about 23 days ago)
Last Updated
2026-07-31 (about 23 days ago)