CVE-2026-14315
Received Received - Intake

Unauthenticated Conversion Event Forgery in Pixel Tag Manager for WooCommerce

Vulnerability report for CVE-2026-14315, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: WPScan

Description

The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pixel_tag_manager woocommerce to 2.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Pixel Tag Manager for WooCommerce WordPress plugin before version 2.2.1. It lacks an authorization check on an AJAX action, allowing unauthenticated users to forge e-commerce conversion events. These events are sent to the site's configured advertising conversion APIs using the site's stored credentials.

Detection Guidance

To detect this vulnerability, check if the Pixel Tag Manager for WooCommerce plugin is installed and verify its version. If it is version 2.2.1 or below, it is vulnerable. Look for unauthorized AJAX conversion events being submitted to advertising APIs.

Impact Analysis

An attacker could exploit this to submit fake conversion events, potentially skewing advertising metrics or leading to unauthorized use of your site's credentials for ad tracking. This may result in financial losses or reputational damage if ad campaigns are compromised.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by allowing unauthorized data processing. Unauthenticated users could submit forged conversion events, which may lead to improper handling of user data or tracking without consent, violating GDPR's data protection principles and HIPAA's requirements for safeguarding protected health information.

Mitigation Strategies

Update the Pixel Tag Manager for WooCommerce plugin to version 2.2.1 or later to address the missing authorization check.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14315. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart