Beta

Report

Pixel Cat <= 2.6.1 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS)

Unauthenticated
Published
2021-11-14

The Pixel Cat – Conversion Pixel Manager WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks

CVSS

Score:6.1

Severity:Medium

Version: 2.6.1

There is a patch available in v2.6.2 and we strongly recommend you update to this version as soon as possible.