Unauthorized Access Vulnerability in Pixel Tag Manager for WooCommerce by WordPress
CVE-2026-14315
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2026
Badges
What is CVE-2026-14315?
The Pixel Tag Manager for WooCommerce plugin prior to version 2.2.1 is susceptible to an authorization check failure in one of its AJAX actions. This vulnerability allows unauthenticated users to exploit the system by submitting forged e-commerce conversion events. The unauthorized use can lead to manipulation of the site's configured server-side advertising conversion APIs, utilizing the stored credentials of the site. Such an exploitation poses significant risks to the integrity and security of e-commerce operations.
Affected Version(s)
Pixel Tag Manager for WooCommerce 0 < 2.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.