CVE-2026-14315 PUBLISHED

Pixel Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission

Assigner: WPScan
Reserved: 01.07.2026 Published: 01.08.2026 Updated: 01.08.2026

The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials.

Product Status

Vendor Unknown
Product Pixel Tag Manager for WooCommerce
Versions Default: unaffected
  • affected from 0 to 2.2.1 (excl.)

Credits

  • Pedro Pinho finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE