CVE · Critical

CVE-2021-24922 — Pixel Cat – Conversion Pixel Manager [facebook-conversion-pixel] < 2.6.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24922 Pixel Cat – Conversion Pixel Manager [facebook-conversion-pixel] < 2.6.3 Cross-Site Request Forgery (CSRF) Critical 9.0 < 2.6.3 2.6.3 2021-11-15

CVE-2021-24922

The Pixel Cat – Conversion Pixel Manager plugin versions prior to 2.6.3 contained a cross-site request forgery vulnerability in its settings page due to missing CSRF protection. Additionally, the plugin failed to properly sanitize and escape certain settings values, enabling attackers to inject malicious scripts that would execute when administrators viewed the affected pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.