Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Win3

#49935of 56,330
5.3Total CVSS
Vulnerabilities · 1
PT-2026-67128
5.3
2026-08-01
WordPress · Pixelyoursite · CVE-2026-18059
**Name of the Vulnerable Software and Affected Versions** PixelYourSite – Your smart PIXEL (TAG) & API Manager versions prior to 11.2.2 **Description** The plugin is subject to sensitive information exposure through the `getWooPurchaseEventParams` function. Unauthenticated attackers can extract WooCommerce purchase metadata, such as product names, product IDs, quantities, per-item prices, order totals, currency, and order/transaction IDs, for any existing order. This occurs because the plugin resolves the order using only the URL path variable and outputs the full `woo purchase` tracking payload into the page HTML via the `pysOptions` JavaScript object for Facebook, Google Analytics, and Google Tag Manager integrations, even if an invalid or arbitrary order key is provided. **Recommendations** Update to a version newer than 11.2.1.