Pixelyoursite develops WordPress plugins and ecommerce integrations, including its core plugin and product catalog feed extensions, that operate in the web-application and e-commerce tier where they handle user input and site configuration. The vendor's vulnerability profile centers on common web-application weaknesses: cross-site scripting in page generation, cross-site request forgery in administrative functions, and authentication gaps, which reflect the plugin's interaction with user-supplied data and WordPress administrative interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pixelyoursite over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7870HIGH The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all versions up to, and | Sep 4, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-49824HIGH Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite Product Catalog Feed by PixelYourSite.This issue affects Product Catalog Feed by PixelYourSite: from n/a through 2. | Dec 17, 2023 | 8.8 | 21 | NO | NO |
CVE-2023-1805MEDIUM The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Refl | May 2, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-1804MEDIUM The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter before outputting it back in an attribute, leading to a Refl | May 2, 2023 | 6.1 | 21 | NO | NO |
CVE-2018-0578MEDIUM Cross-site scripting vulnerability in PixelYourSite plugin prior to version 5.3.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vecto | May 14, 2018 | 5.4 | 19 | NO | NO |
CVE-2023-2584MEDIUM The PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.3.6 (9.6.1 in the Pro version) due to ins | Jun 9, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-22700MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 9.3.0 versions. | Mar 13, 2023 | 4.3 | 17 | NO | NO |
CVE-2024-37447MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager allows Sto | Jul 21, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pixelyoursite.
Media articles that mention a CVE ID that affects a product developed by Pixelyoursite — matched by CVE ID, not by vendor name.