Cross Site Scripting Vulnerability in PixelYourSite by WordPress
CVE-2026-95530

6.5MEDIUM

What is CVE-2026-95530?

A Cross Site Scripting (XSS) vulnerability has been identified in the PixelYourSite plugin for WordPress versions up to 11.4.1, allowing attackers to inject malicious scripts into web pages viewed by other users. This could lead to unwanted actions performed on behalf of users, compromising site integrity and user data security. It is essential for users of affected versions to apply the latest updates and patch their installations to mitigate these risks.

Affected Version(s)

PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Intrudify | Patchstack Bug Bounty Program
.