Executive brief
The Pixel Manager for WooCommerce plugin for WordPress, which helps businesses track marketing data, contains a security flaw in how it handles web requests. An unauthorized person can send fake purchase or conversion data to the website's advertising accounts (like Facebook or Google Ads) using the site's own credentials. This can lead to inaccurate marketing analytics, wasted advertising spend, and corrupted sales data.
Technical details
The vulnerability is an Improper Authorization (CWE-284) flaw within an AJAX handler in the Pixel Manager for WooCommerce plugin. Due to a missing capability check or nonce validation on a specific AJAX action, unauthenticated remote attackers can trigger server-side requests to external advertising APIs. By exploiting this, an attacker can submit fraudulent conversion events using the site's stored API credentials, potentially impacting the integrity of marketing data and advertising algorithms. The issue is resolved in version 2.2.1.
Affected products
- SweetCode Pixel Manager for WooCommerce < 2.2.1
Timeline
- 2026-07-20: disclosed
- 2026-07-20: advisory
- 2026-08-01: patched: NVD publication date; fix available in 2.2.1