WordPress Plugin Vulnerabilities

Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX

Description

The plugin registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access token. This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.

Proof of Concept

Affects Plugins

Fixed in 1.5.4

References

Classification

Type
SSRF
OWASP top 10
CWE

Miscellaneous

Original Researcher
Md Amin Ullah Sheikh
Submitter
Md Amin Ullah Sheikh
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-07-20 (about 1 month ago)
Added
2026-07-20 (about 1 month ago)
Last Updated
2026-07-20 (about 1 month ago)

Other