CVE-2026-18059
Received Received - Intake

Sensitive Information Exposure in PixelYourSite WordPress Plugin

Vulnerability report for CVE-2026-18059, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: Wordfence

Description

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.2.1 via the getWooPurchaseEventParams. This makes it possible for unauthenticated attackers to extract WooCommerce purchase metadata β€” including product names, product IDs, quantities, per-item prices, order totals, currency, and order/transaction IDs β€” for any existing order by supplying an invalid or arbitrary order key. This is exploitable against any known or enumerated order ID, as the plugin resolves the order from the URL path variable alone and emits the full woo_purchase tracking payload into the page HTML via the pysOptions JavaScript object across its Facebook, Google Analytics, and Google Tag Manager integrations regardless of key validity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pixel_yoursite your_smart_pixel_tag_api_manager to 11.2.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The PixelYourSite WordPress plugin up to version 11.2.1 has a vulnerability that allows unauthenticated attackers to access sensitive WooCommerce order data. By providing an invalid order key, attackers can extract details like product names, IDs, quantities, prices, order totals, currency, and transaction IDs from any existing order. The plugin exposes this data in the page HTML through the pysOptions JavaScript object.

Detection Guidance

Check WordPress sites using PixelYourSite plugin versions up to 11.2.1. Inspect page HTML for exposed woo_purchase tracking data in JavaScript objects like pysOptions. Look for order metadata such as product names, IDs, quantities, prices, or order IDs in page source.

Impact Analysis

This vulnerability allows attackers to steal sensitive order information from your WooCommerce store without authentication. If exploited, it could lead to data breaches exposing customer purchase details, financial information, and order history. This may erode customer trust and potentially violate privacy regulations.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and other privacy regulations by exposing personal and financial data without authorization. GDPR requires protecting personal data, and unauthorized access may result in violations. HIPAA may also be affected if the exposed data includes protected health information.

Mitigation Strategies

Update PixelYourSite plugin to the latest version beyond 11.2.1 immediately. If update is unavailable, disable the plugin until a patch is released. Review server logs for suspicious requests targeting order endpoints or unusual data exposure patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18059. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart