Sensitive Information Exposure in PixelYourSite WordPress Plugin
CVE-2026-18059
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-18059?
The PixelYourSite plugin for WordPress, specifically in versions up to and including 11.2.1, is susceptible to a flaw that allows unauthenticated attackers to access sensitive WooCommerce purchase metadata. This vulnerability enables attackers to extract crucial information, such as product names, IDs, quantities, prices, order totals, currency, and transaction IDs by providing an invalid or arbitrary order key. The vulnerability is particularly concerning because the plugin's design allows the resolution of orders solely through the URL, exposing the full WooCommerce tracking payload via the pysOptions JavaScript object in the page's HTML. This data is sent through integrations with Facebook, Google Analytics, and Google Tag Manager, compromising user privacy and data security if exploited.
Affected Version(s)
PixelYourSite β Your smart PIXEL (TAG) & API Manager 0 <= 11.2.1
PixelYourSite Pro β Your smart PIXEL (TAG) Manager 0 < 12.6.1