Sensitive Information Exposure in PixelYourSite WordPress Plugin
CVE-2026-18059

5.3MEDIUM

What is CVE-2026-18059?

The PixelYourSite plugin for WordPress, specifically in versions up to and including 11.2.1, is susceptible to a flaw that allows unauthenticated attackers to access sensitive WooCommerce purchase metadata. This vulnerability enables attackers to extract crucial information, such as product names, IDs, quantities, prices, order totals, currency, and transaction IDs by providing an invalid or arbitrary order key. The vulnerability is particularly concerning because the plugin's design allows the resolution of orders solely through the URL, exposing the full WooCommerce tracking payload via the pysOptions JavaScript object in the page's HTML. This data is sent through integrations with Facebook, Google Analytics, and Google Tag Manager, compromising user privacy and data security if exploited.

Affected Version(s)

PixelYourSite – Your smart PIXEL (TAG) & API Manager 0 <= 11.2.1

PixelYourSite Pro – Your smart PIXEL (TAG) Manager 0 < 12.6.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Win3
.