PT-2026-67034 · WordPress · Pixelavo
CVE-2026-13604
·
Published
2026-08-01
·
Updated
2026-08-01
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pixelavo versions prior to 1.5.4
Description
The plugin registers an unauthenticated AJAX action that forwards client-supplied event data to the Facebook Conversions API using the administrator's stored access token. This action is protected only by a nonce (a number used once to prevent replay attacks) that is publicly emitted on every front-end page. Consequently, an unauthenticated visitor can inject arbitrary conversion events into the administrator's Facebook ads account, potentially exhausting the configured API quota. The affected endpoint is
pixelavo event.Recommendations
Update Pixelavo to version 1.5.4 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pixelavo