CVE-2026-27072 describes a Stored Cross-site Scripting (XSS) vulnerability in the PixelYourSite – Your smart PIXEL (TAG) Manager plugin, affecting versions up to and including 11.2.0.1. This vulnerability allows for improper neutralization of input during web page generation. It carries a CVSS score of 7.1 (HIGH), indicating that an unauthenticated attacker could exploit it with low attack complexity, requiring user interaction, to achieve partial confidentiality, integrity, and availability impacts. Currently, there is no known active exploitation, publicly available exploit code (e.g., Metasploit, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| PixelYourSite | PixelYourSite – Your Smart PIXEL (TAG) Manager | >= 0, <= 11.2.0.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.