CVE-2026-13604
Received Received - Intake

Unauthenticated AJAX Event Injection in Pixelavo WordPress Plugin

Vulnerability report for CVE-2026-13604, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: WPScan

Description

The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access token. This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pixelavo wordpress_plugin to 1.5.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Pixelavo WordPress plugin before version 1.5.4 has a flaw where it exposes an AJAX action that can be triggered without authentication. This action uses a nonce that is publicly available on every front-end page, allowing anyone to send requests. The plugin forwards user-supplied event data to Facebook's Conversions API using the admin's stored access token, enabling unauthenticated users to inject fake conversion events and consume the API quota.

Detection Guidance

Check if the Pixelavo WordPress plugin version is below 1.5.4. Inspect network traffic for unauthorized AJAX requests to Facebook Conversions API endpoints. Review server logs for unusual conversion event submissions.

Impact Analysis

If you use this plugin, an attacker could exploit it to send unauthorized conversion events to your Facebook ads account. This may drain your API quota, disrupt ad campaigns, and potentially lead to financial losses or misreported analytics. The attack requires no authentication, making it easier for malicious actors to target your site.

Compliance Impact

This vulnerability does not directly affect GDPR or HIPAA compliance as described. The issue involves unauthenticated API event injection into Facebook ads, which primarily impacts data integrity and access control rather than regulated data handling.

Mitigation Strategies

Update the Pixelavo WordPress plugin to version 1.5.4 or later to address the unauthenticated AJAX action vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13604. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart