plugin

Official Facebook Pixel Vulnerabilities

7 known security issues reported for the Official Facebook Pixel WordPress plugin. Most recent disclosed Jul 31, 2026.

3 high

Running Official Facebook Pixel on your site? Check whether your installed version is affected.

Scan your site free

Meta pixel for WordPress <= 5.2.1 - Unauthenticated Stored Cross-Site Scripting

high

The Meta pixel for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a us...

CVSS:
7.2
Affected:
up to 5.2.1
Fixed in:
5.2.2
Disclosed:
Jul 31, 2026

CVE-2026-66705 on NVD →

Meta pixel for WordPress [official-facebook-pixel] < 3.0.0

unknown

[en] The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method in the plugin that could be used to achieve remote code execution.

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Apr 12, 2021

CVE-2021-24217 on NVD →

Meta pixel for WordPress [official-facebook-pixel] >= 3.0.0 - <= 3.0.3

unknown

[en] The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF due to a lack of nonce protection. The settings in the saveFbeSettings function had no sanitization allowing for script tags to be saved.

Affected:
3.0.0 – 3.0.3
Fixed in:
3.0.3
Disclosed:
Apr 12, 2021

CVE-2021-24218 on NVD →

Facebook for WordPress <= 3.0.3 - Cross-site Request Forgery to Stored Cross-site Scripting and Settings Deletion via wp_ajax_(save|delete)_fbe_settings

high

The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF due to a lack of nonce protection. The settings in the saveFbeSettings function had no sanitization allowing for script tags to be saved.

CVSS:
8.8
Affected:
3.0.0 – 3.0.4
Fixed in:
3.0.4
Disclosed:
Mar 25, 2021

CVE-2021-24218 on NVD →

Meta pixel for WordPress <= 2.2.2 - PHP Object Injection

high

The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method in the plugin that could be used to achieve remote code execution.

CVSS:
8.1
Affected:
up to 2.2.2
Fixed in:
3.0.0
Disclosed:
Mar 25, 2021

CVE-2021-24217 on NVD →

Meta pixel for WordPress [official-facebook-pixel] < 3.0.0

unknown

PHP Object Injection vulnerability discovered by WordFence in WordPress Facebook for WordPress plugin (versions <= 2.2.2).

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Mar 25, 2021

Meta pixel for WordPress [official-facebook-pixel] >= 3.0.0 - <= 3.0.3

unknown

Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability discovered by WordFence in WordPress Facebook for WordPress plugin (versions 3.0.0 – 3.0.3).

Affected:
3.0.0 – 3.0.3
Fixed in:
3.0.3
Disclosed:
Mar 25, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database