CVE-2026-95530: WordPress PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 11.4.1 - Cross Site Scripting (XSS) vulnerability
Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress PixelYourSite – Your smart PIXEL (TAG) Managerto a version that resolves this vulnerability.Fixed in 11.4.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs Subscriber-level access to a WordPress site using an affected PixelYourSite – Your smart PIXEL (TAG) Manager version. Exploitation also requires user interaction.
What impact can successful exploitation have?
Successful cross-site scripting can affect confidentiality, integrity, and availability at a low level. The vulnerability has a CVSS severity of medium (6.5) and can affect resources beyond the vulnerable component's security scope.
Which plugin versions are affected?
PixelYourSite – Your smart PIXEL (TAG) Manager versions 11.4.1 and earlier are affected.