Impact
The Pixelavo WordPress plugin registers an unauthenticated AJAX action that is gated only by a nonce emitted publicly on each front‑end page. The action forwards client‑supplied event data to the administrator’s configured Facebook Conversions API using the stored access token. This allows any visitor to inject arbitrary conversion events, causing incorrect analytics data and exhausting the API quota.
Affected Systems
The vulnerability affects the Pixelavo WordPress plugin prior to version 1.5.4, published by Unknown:Pixelavo. Any WordPress site that has a vulnerable instance of this plugin installed is exposed.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low likelihood of active exploitation, and the vulnerability is not listed in CISA’s KEV catalog. However, since the AJAX endpoint is publicly reachable and requires no authentication, an attacker can trigger the flaw simply by sending crafted requests to the plugin’s endpoint from any IP. If abused, the attacker could inflate conversion metrics and deplete the site’s Facebook API quota. The CVSS score of 5.3 indicates moderate severity.
OpenCVE Enrichment