PT-2026-67034 · WordPress · Pixelavo

CVE-2026-13604

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pixelavo versions prior to 1.5.4
Description The plugin registers an unauthenticated AJAX action that forwards client-supplied event data to the Facebook Conversions API using the administrator's stored access token. This action is protected only by a nonce (a number used once to prevent replay attacks) that is publicly emitted on every front-end page. Consequently, an unauthenticated visitor can inject arbitrary conversion events into the administrator's Facebook ads account, potentially exhausting the configured API quota. The affected endpoint is pixelavo event.
Recommendations Update Pixelavo to version 1.5.4 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13604

Affected Products

Pixelavo