CVE-2026-18059: PixelYourSite <= 11.2.1 - Unauthenticated Sensitive Information Exposure via Order-Received Endpoint Missing Key Validation

Published Aug 1, 2026
·
Updated

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.2.1 via the getWooPurchaseEventParams. This makes it possible for unauthenticated attackers to extract WooCommerce purchase metadata — including product names, product IDs, quantities, per-item prices, order totals, currency, and order/transaction IDs — for any existing order by supplying an invalid or arbitrary order key. This is exploitable against any known or enumerated order ID, as the plugin resolves the order from the URL path variable alone and emits the full woopurchase tracking payload into the page HTML via the pysOptions JavaScript object across its Facebook, Google Analytics, and Google Tag Manager integrations regardless of key validity.

Affected Software

1 affected component
PixelYourSite Your smart PIXEL (TAG) & API Manager plugin for WordPress<=11.2.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade PixelYourSite (WordPress plugin) to a version that resolves this vulnerability.

    Fixed in 11.2.1
  2. Configuration

    Implement missing key validation for the getWooPurchaseEventParams logic so that unauthenticated requests with invalid/arbitrary order keys do not resolve orders or output purchase metadata in the page HTML/JS pysOptions.

    PixelYourSite – Your smart PIXEL (TAG) & API Manager (WordPress) Key validation for getWooPurchaseEventParams order-resolution = Require valid order key before resolving the order from the URL path variable and before emitting the woo_purchase tracking payload into pysOptions

Event History

Aug 1, 2026
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-18059?

CVE-2026-18059 has a medium severity rating of 5.3.

2

How do I fix CVE-2026-18059?

To fix CVE-2026-18059, update the PixelYourSite plugin to a version later than 11.2.1.

3

What type of vulnerability is CVE-2026-18059?

CVE-2026-18059 is classified as an unauthenticated sensitive information exposure vulnerability.

4

Who is affected by CVE-2026-18059?

CVE-2026-18059 affects all versions of the PixelYourSite plugin for WordPress up to and including 11.2.1.

5

What information can be exposed due to CVE-2026-18059?

CVE-2026-18059 allows unauthenticated attackers to extract WooCommerce purchase metadata.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203