plugin

Facebook Conversion Pixel Vulnerabilities

4 known security issues reported for the Facebook Conversion Pixel WordPress plugin. Most recent disclosed Sep 23, 2024.

1 high 3 medium

Running Facebook Conversion Pixel on your site? Check whether your installed version is affected.

Scan your site free

Pixel Cat – Conversion Pixel Manager <= 3.0.5 - Reflected Cross-Site Scripting

medium

The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.0.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 3.0.5
Fixed in:
3.0.6
Disclosed:
Sep 23, 2024

CVE-2024-8544 on NVD →

Pixel Cat – Conversion Pixel Manager <= 2.6.3 - Reflected Cross-Site Scripting

medium

The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 2.6.3 due to missing input and output sanitization of some user generated URLs.

CVSS:
6.1
Affected:
up to 2.6.3
Fixed in:
2.6.4
Disclosed:
Nov 18, 2021

Pixel Cat – Conversion Pixel Manager <= 2.6.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

high

The Pixel Cat – Conversion Pixel Manager WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks

CVSS:
8.8
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
Nov 15, 2021

CVE-2021-24922 on NVD →

Pixel Cat Lite <= 2.6.2 - Admin+ Stored Cross-Site Scripting

medium

The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVSS:
4.8
Affected:
up to 2.6.2
Fixed in:
2.6.3
Disclosed:
Nov 15, 2021

CVE-2021-24972 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database