Sceawere
Vulnerability Detail
CVE-2026-94674UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Contributor XSS in Pixel Manager
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- SweetCode
- Product
- Pixel Manager for WooCommerce
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-30T13:17:27.403Z",
"pubdate": "2026-09-30T13:17:27.403Z",
"executiveSummary": "The Pixel Manager for WooCommerce plugin, specifically in versions 1.69.0 and below, contains a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability originates from improper neutralization of user-supplied input by users with the Contributor role, which is then rendered unsanitized in the administrative dashboard.\nThe flaw allows an authenticated attacker with contributor-level permissions to inject malicious JavaScript payloads into the application.\nSuccessful exploitation results in the execution of arbitrary scripts within the context of an administrator's browser session, leading to potential account takeover, unauthorized administrative actions, and data exfiltration.\nThe risk is categorized as high due to the potential for privilege escalation and the compromise of administrative integrity within the WordPress environment.\nExploitation requires the attacker to be authenticated as a user with at least the Contributor role.",
"technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), stemming from insufficient input validation and output encoding within the Pixel Manager for WooCommerce plugin.\nIn versions <= 1.69.0, the plugin fails to adequately sanitize inputs provided by users with the Contributor role before storing them in the WordPress database or reflecting them within the plugin's administrative settings pages.\nThe attack flow begins when an authenticated contributor submits malicious payload strings into fields processed by the plugin. Because the plugin does not implement proper context-aware output encoding (such as esc_html(), esc_attr(), or json_encode()) when rendering these stored values in the WordPress admin dashboard, the browser interprets the input as executable code rather than plain text.\nWhen an administrator accesses the compromised settings page or dashboard module, the injected JavaScript executes within the security context of the administrator's session.\nThis execution allows the attacker to perform actions on behalf of the administrator, such as modifying plugin configurations, injecting further malicious scripts, or exfiltrating sensitive session cookies and CSRF tokens.\nThe vulnerable component involves the plugin's backend administrative interface, specifically where user-provided configuration data is retrieved and reflected without adequate verification.\nThis issue represents a failure in the 'data integrity' and 'input validation' security controls, allowing an attacker with limited privileges to transcend their permission boundaries by leveraging the trust inherently granted to the administrator's browser session.\nPost-exploitation, the impact is severe, as the attacker can manipulate the plugin's behavior, potentially interfering with e-commerce tracking, altering tracking scripts, or performing unauthorized administrative functions that persist until the payload is manually removed from the database.\nThe vulnerability is persistent, meaning the malicious payload will execute every time an authorized user views the affected administrative component until the underlying data is purged."
}