Tracking Code Manager <= 2.6.0 - Cross-Site Request Forgery
medium
The Tracking Code Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they...
- CVSS:
- 4.3
- Affected:
- up to 2.6.0
- Fixed in:
- 2.7.0
- Disclosed:
- Aug 5, 2026
CVE-2026-28172 on NVD →
Tracking Code Manager [tracking-code-manager] < 2.4.0
unknown
[en] The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.0
- Disclosed:
- Jan 30, 2025
CVE-2024-10309 on NVD →
Tracking Code Manager <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tracking code field in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to...
- CVSS:
- 6.4
- Affected:
- up to 2.3.0
- Fixed in:
- 2.4.0
- Disclosed:
- Dec 23, 2024
CVE-2024-8721 on NVD →
Tracking Code Manager [tracking-code-manager] < 2.2.0
unknown
[en] Missing Authorization vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.1.0.
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Jun 9, 2024
CVE-2024-31347 on NVD →
Tracking Code Manager <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to in...
- CVSS:
- 4.4
- Affected:
- up to 2.2.0
- Fixed in:
- 2.3.0
- Disclosed:
- Jun 3, 2024
CVE-2024-6335 on NVD →
Tracking Code Manager <= 2.1.0 - Missing Authorization via change_order()
medium
The Tracking Code Manager plugin for WordPress is vulnerable to unauthorized modification due to a missing capability check on the change_order() function in versions up to, and including, 2.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to change the order of a menu.
- CVSS:
- 4.3
- Affected:
- up to 2.1.0
- Fixed in:
- 2.2.0
- Disclosed:
- Apr 5, 2024
CVE-2024-31347 on NVD →
Tracking Code Manager [tracking-code-manager] < 2.1.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.0.16.
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.0
- Disclosed:
- Mar 21, 2024
CVE-2024-2579 on NVD →
Tracking Code Manager <= 2.0.16 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to i...
- CVSS:
- 4.4
- Affected:
- up to 2.0.16
- Fixed in:
- 2.1.0
- Disclosed:
- Mar 18, 2024
CVE-2024-2579 on NVD →
Tracking Code Manager < 1.11.5 - Denial of Service
high
The Tracking Code Manager for WordPress is vulnerable to Denial of Service attacks in versions up to, and including, 1.11.4. This is due to the ability of users to make a recursive call to the 'tcmp_do_action' function. Due to an additional Cross-Site Request Forgery vulnerability, this makes it possible for unauthenti...
- CVSS:
- 7.5
- Affected:
- up to 1.11.4
- Fixed in:
- 1.11.5
- Disclosed:
- May 10, 2017
Tracking Code Manager < 1.11.5 - Cross-Site Scripting
medium
The Tracking Code Manager for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tcmp_action’ parameter in versions up to, and including, 1.11.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 1.11.4
- Fixed in:
- 1.11.5
- Disclosed:
- May 10, 2017
Tracking Code Manager [tracking-code-manager] < 1.11.5
unknown
The Tracking Code Manager for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tcmp_action’ parameter in versions up to, and including, 1.11.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- Affected:
- up to 1.11.5
- Fixed in:
- 1.11.5
- Disclosed:
- May 10, 2017
Tracking Code Manager [tracking-code-manager] < 1.11.5
unknown
The Tracking Code Manager for WordPress is vulnerable to Denial of Service attacks in versions up to, and including, 1.11.4. This is due to the ability of users to make a recursive call to the 'tcmp_do_action' function. Due to an additional Cross-Site Request Forgery vulnerability, this makes it possible for unauthenti...
- Affected:
- up to 1.11.5
- Fixed in:
- 1.11.5
- Disclosed:
- May 10, 2017
Tracking Code Manager [tracking-code-manager] < 2.3.0
unknown
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
CVE-2024-6335 on NVD →
Tracking Code Manager [tracking-code-manager] < 2.4.0
unknown
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.0
CVE-2024-8721 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database