CVE · Medium

CVE-2024-8544 — Pixel Cat – Conversion Pixel Manager [facebook-conversion-pixel] < 3.0.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8544 Pixel Cat – Conversion Pixel Manager [facebook-conversion-pixel] < 3.0.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.0.6 3.0.6 2024-09-23

CVE-2024-8544

The Pixel Cat – Conversion Pixel Manager plugin for WordPress has a security flaw affecting all versions up to 3.0.5, where the URL generated by add_query_arg is not properly sanitized, allowing malicious actors to inject unwanted JavaScript code that can execute if a user clicks on a manipulated link without needing any authentication credentials. This vulnerability enables attackers to potentially inject arbitrary web scripts into pages, compromising user security and potentially leading to further attacks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.