CVE Explorer
CVE-2026-13604
The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access token. This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Pixelavo","vendor":"Unknown","versions":[{"lessThan":"1.5.4","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ddcaef2e08d2e0f838bca677abd68ae9cae0c0bf8576014fdedc5247a0d0ec27 · sha256:5d83e916caf3fd3b… · /containers/cna/affected/0
CWE assertions
1 source assertion{"description":"CWE-918 Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ddcaef2e08d2e0f838bca677abd68ae9cae0c0bf8576014fdedc5247a0d0ec27 · sha256:5d83e916caf3fd3b… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/766c961e-e5aa-4ebe-8107-032f46316f91/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ddcaef2e08d2e0f838bca677abd68ae9cae0c0bf8576014fdedc5247a0d0ec27 · sha256:5d83e916caf3fd3b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.