WordPress · Pixelyoursite · CVE-2026-18059
**Name of the Vulnerable Software and Affected Versions**
PixelYourSite – Your smart PIXEL (TAG) & API Manager versions prior to 11.2.2
**Description**
The plugin is subject to sensitive information exposure through the `getWooPurchaseEventParams` function. Unauthenticated attackers can extract WooCommerce purchase metadata, such as product names, product IDs, quantities, per-item prices, order totals, currency, and order/transaction IDs, for any existing order. This occurs because the plugin resolves the order using only the URL path variable and outputs the full `woo purchase` tracking payload into the page HTML via the `pysOptions` JavaScript object for Facebook, Google Analytics, and Google Tag Manager integrations, even if an invalid or arbitrary order key is provided.
**Recommendations**
Update to a version newer than 11.2.1.