Cross-Site Request Forgery Risk in PixelYourSite for WordPress
CVE-2025-10588
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 October 2025
What is CVE-2025-10588?
The PixelYourSite plugin for WordPress features a security flaw that allows attackers to exploit Cross-Site Request Forgery (CSRF) vulnerabilities. This issue stems from inadequate nonce validation in the adminEnableGdprAjax() function, which facilitates unauthorized changes to GDPR settings. Attackers can potentially manipulate these settings if they successfully deceive a site administrator into triggering a malicious action, such as clicking a crafted link. It is critical for administrators to ensure plugin updates are applied to mitigate this risk.
Affected Version(s)
PixelYourSite – Your smart PIXEL (TAG) & API Manager * <= 11.1.2