plugin

Tracking Code Manager Vulnerabilities

14 known security issues reported for the Tracking Code Manager WordPress plugin. Most recent disclosed Aug 5, 2026.

1 high 6 medium

Running Tracking Code Manager on your site? Check whether your installed version is affected.

Scan your site free

Tracking Code Manager <= 2.6.0 - Cross-Site Request Forgery

medium

The Tracking Code Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they...

CVSS:
4.3
Affected:
up to 2.6.0
Fixed in:
2.7.0
Disclosed:
Aug 5, 2026

CVE-2026-28172 on NVD →

Tracking Code Manager [tracking-code-manager] < 2.4.0

unknown

[en] The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

Affected:
up to 2.4.0
Fixed in:
2.4.0
Disclosed:
Jan 30, 2025

CVE-2024-10309 on NVD →

Tracking Code Manager <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tracking code field in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to...

CVSS:
6.4
Affected:
up to 2.3.0
Fixed in:
2.4.0
Disclosed:
Dec 23, 2024

CVE-2024-8721 on NVD →

Tracking Code Manager [tracking-code-manager] < 2.2.0

unknown

[en] Missing Authorization vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.1.0.

Affected:
up to 2.2.0
Fixed in:
2.2.0
Disclosed:
Jun 9, 2024

CVE-2024-31347 on NVD →

Tracking Code Manager <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to in...

CVSS:
4.4
Affected:
up to 2.2.0
Fixed in:
2.3.0
Disclosed:
Jun 3, 2024

CVE-2024-6335 on NVD →

Tracking Code Manager <= 2.1.0 - Missing Authorization via change_order()

medium

The Tracking Code Manager plugin for WordPress is vulnerable to unauthorized modification due to a missing capability check on the change_order() function in versions up to, and including, 2.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to change the order of a menu.

CVSS:
4.3
Affected:
up to 2.1.0
Fixed in:
2.2.0
Disclosed:
Apr 5, 2024

CVE-2024-31347 on NVD →

Tracking Code Manager [tracking-code-manager] < 2.1.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.0.16.

Affected:
up to 2.1.0
Fixed in:
2.1.0
Disclosed:
Mar 21, 2024

CVE-2024-2579 on NVD →

Tracking Code Manager <= 2.0.16 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to i...

CVSS:
4.4
Affected:
up to 2.0.16
Fixed in:
2.1.0
Disclosed:
Mar 18, 2024

CVE-2024-2579 on NVD →

Tracking Code Manager < 1.11.5 - Denial of Service

high

The Tracking Code Manager for WordPress is vulnerable to Denial of Service attacks in versions up to, and including, 1.11.4. This is due to the ability of users to make a recursive call to the 'tcmp_do_action' function. Due to an additional Cross-Site Request Forgery vulnerability, this makes it possible for unauthenti...

CVSS:
7.5
Affected:
up to 1.11.4
Fixed in:
1.11.5
Disclosed:
May 10, 2017

Tracking Code Manager < 1.11.5 - Cross-Site Scripting

medium

The Tracking Code Manager for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tcmp_action’ parameter in versions up to, and including, 1.11.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 1.11.4
Fixed in:
1.11.5
Disclosed:
May 10, 2017

Tracking Code Manager [tracking-code-manager] < 1.11.5

unknown

The Tracking Code Manager for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tcmp_action’ parameter in versions up to, and including, 1.11.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 1.11.5
Fixed in:
1.11.5
Disclosed:
May 10, 2017

Tracking Code Manager [tracking-code-manager] < 1.11.5

unknown

The Tracking Code Manager for WordPress is vulnerable to Denial of Service attacks in versions up to, and including, 1.11.4. This is due to the ability of users to make a recursive call to the 'tcmp_do_action' function. Due to an additional Cross-Site Request Forgery vulnerability, this makes it possible for unauthenti...

Affected:
up to 1.11.5
Fixed in:
1.11.5
Disclosed:
May 10, 2017

Tracking Code Manager [tracking-code-manager] < 2.3.0

unknown
Affected:
up to 2.3.0
Fixed in:
2.3.0

CVE-2024-6335 on NVD →

Tracking Code Manager [tracking-code-manager] < 2.4.0

unknown
Affected:
up to 2.4.0
Fixed in:
2.4.0

CVE-2024-8721 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database