PLUGIN SECURITY

Is Pixel Cat – Conversion Pixel Manager safe?

Add Meta & Facebook Pixel, Google Analytics (GA4) and any header script to your site. Everything you need to track users, ads, events & conversions.

What this plugin does

  • Slug: facebook-conversion-pixel
  • Author: fatcatapps
  • 40000+ active installs
  • 80/100 rating (41 reviews on wordpress.org)
  • 1377147 all-time downloads
  • On WordPress.org since 2014-06-12

CAPIConversions APIcustom audiencesFacebook PixelMeta Pixel

Maintenance status

  • Latest known version: 3.4.0
  • Last updated: 2026-08-16 2:40am GMT
  • Tested up to WordPress: 7.1

Known vulnerabilities

3 known CVEs on file for Pixel Cat – Conversion Pixel Manager. Reported between 2021 and 2024.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8544 Pixel Cat – Conversion Pixel Manager [facebook-conversion-pixel] < 3.0.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.0.6 3.0.6 2024-09-23 ✓ fixed in latest
Pixel Cat – Conversion Pixel Manager [facebook-conversion-pixel] < 2.6.4 Unknown < 2.6.4 2.6.4 2023-11-18 ✓ fixed in latest
Pixel Cat – Conversion Pixel Manager [facebook-conversion-pixel] < 2.6.4 Unknown < 2.6.4 2.6.4 2021-11-18 ✓ fixed in latest
CVE-2021-24922 Pixel Cat – Conversion Pixel Manager [facebook-conversion-pixel] < 2.6.3 Cross-Site Request Forgery (CSRF) Critical 9.0 < 2.6.3 2.6.3 2021-11-15 ✓ fixed in latest
CVE-2021-24972 Pixel Cat – Conversion Pixel Manager [facebook-conversion-pixel] < 2.6.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.6.3 2.6.3 2021-11-15 ✓ fixed in latest
Pixel Cat – Conversion Pixel Manager [facebook-conversion-pixel] < 2.6.4 Unknown < 2.6.4 2.6.4 ✓ fixed in latest
Pixel Cat Lite < 2.6.4 - Reflected Cross-Site Scripting Unknown < 2.6.4 2.6.4 ✓ fixed in latest

How to fix it

Keep Pixel Cat – Conversion Pixel Manager updated — 3.4.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.