CVE-2026-94674: WordPress Pixel Manager for WooCommerce plugin <= 1.69.0 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions.
Affected Software
1 affected component
WooCommerce Pixel Manager for WooCommerce<=1.69.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Pixel Manager for WooCommerceto a version that resolves this vulnerability.Fixed in 1.69.1
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Contributor-level access to a WordPress site using the affected plugin version. Exploitation also requires user interaction.
2
Which installations are affected?
Pixel Manager for WooCommerce versions 1.69.0 and earlier are affected. The provided information does not state whether the vulnerable behavior is enabled in the default configuration.
3
What impact could successful exploitation have?
Successful cross-site scripting could allow limited disclosure, modification, or disruption in a changed security scope, as reflected by the CVSS vector.