CVE · High

CVE-2021-24218 — Meta pixel for WordPress [official-facebook-pixel] >= 3.0.0 - <= 3.0.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24218 Meta pixel for WordPress [official-facebook-pixel] >= 3.0.0 - <= 3.0.3 Cross-Site Request Forgery (CSRF) High 8.8 3.0.0–3.0.4 3.0.4 2021-03-25

CVE-2021-24218

The Facebook for WordPress plugin versions 3.0.0 through 3.0.3 contained a cross-site request forgery vulnerability in the wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions because they did not implement nonce verification. Additionally, the saveFbeSettings function failed to sanitize input, permitting attackers to inject and store script tags within the plugin settings. These flaws were resolved in version 3.0.4.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.