• Resolved raitchev_alex

    (@raitchev_alex)


    hello, there was important securuty vulnerabilities which seems you fixed in todays 17th Feb Pro version, do you plan to integrate it, as seems very dangerous creating admin users in background and compromising the website… this may wipe your site at all.

Viewing 7 replies - 1 through 7 (of 7 total)
  • Plugin Support pixelyoursitesupport

    (@pixelyoursitesupport)

    There are no security issues in the free version of the plugin, there is no need to issue an update.

    Thread Starter raitchev_alex

    (@raitchev_alex)

    There is! I receive fake orders and this was the problem with the Pro plugin also. Still i receive such last days.

    Plugin Support pixelyoursitesupport

    (@pixelyoursitesupport)

    This forum is dedicated to the free version of the plugin and this one has no vulnerabilities.

    The patch for the pro plugin is available and was already released at the time this discussion started, please update and follow these instructions: https://www.pixelyoursite.com/security-update-pixelyoursite-pro

    Thread Starter raitchev_alex

    (@raitchev_alex)

    I use the free version and indicate the same problem with the plugin with receiving fake orders and executing script in the background. here is the link with the problem:

    redpacketsecurity.com/cve-alert-cve-2026-1844-pixelyoursite-pixelyoursite-pro-your-smart-pixel-tag-manager/?fbclid=IwY2xjawP_5CxleHRuA2FlbQIxMABicmlkETE3OG5sQnBST0xqZjBwc2g1c3J0YwZhcHBfaWQQMjIyMDM5MTc4ODIwMDg5MgABHjLzEu5mfjbOdSQp5uTzCXLgZXYAbG20DTGggZ0cOaxuh1XwRHD6PJGdNGGM_aem_V0U0UZoUfddV6Ai2h3nlOg&__cf_chl_rt_tk=2jKWBn0b5V_cZWddDRg1izi7rHk.Z4C4xlI5pCm23Nw-1771427850-1.0.1.1-oy1wQHj2m0flIa8xkhKoIpDBkPySg4BsfKHRArC.4Xc

    i hope you will have that fixed for free version only as this is critical vulnerability.

    Plugin Support pixelyoursitesupport

    (@pixelyoursitesupport)

    That is the free version log, and this was released on February 11, 2026. It is indeed the version that has the fix, 11.2.0.2. 

    The final fix for the pro version is included in version 12.4.1.

    Recommended Actions:

    1. Update the plugin to the latest version immediately.
    2. Reset all administrator passwords.
    3. Review the list of administrator users and remove any unfamiliar accounts.
    4. Review WooCommerce → Advanced → REST API and delete any unknown or suspicious API keys.
    5. As an extra precaution, you can also regenerate existing REST API keys. Replace them in the services that use them.

    As a precaution, we also recommend enabling two-factor authentication (2FA) for all administrator accounts.

    Plugin Support pixelyoursitesupport

    (@pixelyoursitesupport)

    Thanks for the feedback.

    Search your database for staticsx to find dangerous order data, which can create admin user when viewed.

Viewing 7 replies - 1 through 7 (of 7 total)

The topic ‘Security updates’ is closed to new replies.