Cross Site Scripting Vulnerability in PixelYourSite by WordPress
CVE-2026-95530
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 September 2026
What is CVE-2026-95530?
A Cross Site Scripting (XSS) vulnerability has been identified in the PixelYourSite plugin for WordPress versions up to 11.4.1, allowing attackers to inject malicious scripts into web pages viewed by other users. This could lead to unwanted actions performed on behalf of users, compromising site integrity and user data security. It is essential for users of affected versions to apply the latest updates and patch their installations to mitigate these risks.
Affected Version(s)
PixelYourSite β Your smart PIXEL (TAG) Manager <= 11.4.1