Pixel Cat – Conversion Pixel Manager <= 3.0.5 - Reflected Cross-Site Scripting
medium
The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.0.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 3.0.5
- Fixed in:
- 3.0.6
- Disclosed:
- Sep 23, 2024
CVE-2024-8544 on NVD →
Pixel Cat – Conversion Pixel Manager <= 2.6.3 - Reflected Cross-Site Scripting
medium
The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 2.6.3 due to missing input and output sanitization of some user generated URLs.
- CVSS:
- 6.1
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.4
- Disclosed:
- Nov 18, 2021
Pixel Cat – Conversion Pixel Manager <= 2.6.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
high
The Pixel Cat – Conversion Pixel Manager WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks
- CVSS:
- 8.8
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.2
- Disclosed:
- Nov 15, 2021
CVE-2021-24922 on NVD →
Pixel Cat Lite <= 2.6.2 - Admin+ Stored Cross-Site Scripting
medium
The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
- CVSS:
- 4.8
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Nov 15, 2021
CVE-2021-24972 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database