Description
The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials.
Published: 2026-08-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Pixel Tag Manager for WooCommerce plugin fails to verify authorization on an AJAX action that records e‑commerce conversion events. As a result, anyone can send forged conversion data to the site’s configured server‑side advertising conversion API using the site’s stored credentials. This allows an attacker to poison advertising metrics, inflate conversion counts, or disrupt campaign reporting without authentication, potentially compromising the integrity of advertising attribution and possibly leading to financial loss or audit failures.

Affected Systems

WordPress sites running the Pixel Tag Manager for WooCommerce plugin with versions older than 2.2.1 are affected when the plugin is available to the public. The vulnerability applies regardless of the user role, since no authentication check is performed during the AJAX request.

Risk and Exploitability

The EPSS score is listed as less than 1 %, indicating a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. The absence of access control allows remote unauthenticated submissions, with a CVSS score of 6.5 reflecting moderate severity. The attack vector is inferred to be web‑based via an AJAX call, which can be triggered from any browser or script that can reach the plugin’s endpoint on an unprotected WordPress installation.

Generated by OpenCVE AI on August 4, 2026 at 22:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Pixel Tag Manager for WooCommerce plugin to version 2.2.1 or later, which implements proper authorization checks for the conversion‑event AJAX handler.
  • If an upgrade is not immediately possible, restrict web access to the WooCommerce AJAX endpoints (e.g., through firewall rules or the WordPress REST API restriction plugins) to allow only authenticated requests to reach the conversion‑event action.
  • Implement server‑side validation to reject any conversion event data that originates from IPs not belonging to the site’s configuration, and monitor conversion logs for anomalous entries that may indicate forged submissions.

Generated by OpenCVE AI on August 4, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Pixel Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission Pixel Tag Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission

Tue, 04 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Mon, 03 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 02 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-287

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials.
Title Pixel Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T19:15:36.444Z

Reserved: 2026-07-01T11:39:58.789Z

Link: CVE-2026-14315

cve-icon Vulnrichment

Updated: 2026-08-03T18:46:38.047Z

cve-icon NVD

Status : Received

Published: 2026-08-01T07:16:30.307

Modified: 2026-08-03T19:16:42.683

Link: CVE-2026-14315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:30:05Z

Weaknesses