{"error":0,"message":null,"data":{"name":"GTM4WP &#8211; A Google Tag Manager (GTM) plugin for WordPress","plugin":"duracelltomi-google-tag-manager","link":"https:\/\/wordpress.org\/plugins\/duracelltomi-google-tag-manager\/","latest":"1789452780","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"4f456eb2ef5c02ea946557373f3beec9b2003b2bf480edfaab75fd7cec1ba217","name":"GTM4WP &#8211; A Google Tag Manager (GTM) plugin for WordPress [duracelltomi-google-tag-manager] < 1.15.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.15.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-1707","name":"CVE-2022-1707","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-1707","description":"[en] The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization in versions up to an including 1.15. The affected file is ~\/public\/frontend.php and this could be exploited by unauthenticated attackers.","date":"2022-06-13"},{"id":"c8b0c80ab72331187c54beca07b42091b7aea3a8","name":"WordPress Google Tag Manager plugin <= 1.15 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duracelltomi-google-tag-manager\/vulnerability\/wordpress-google-tag-manager-plugin-1-15-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by Cory Buecker and not_stoppable in WordPress Google Tag Manager plugin (versions <= 1.15).\nUpdate the WordPress Google Tag Manager plugin to the latest available version (at least 1.15.1).","date":"2022-05-19"},{"id":"409ef7dc8ef21a16fcb2b289f98287e8a585c15d","name":"Google Tag Manager for WordPress <= 1.15 - Reflected Cross-Site Scripting via Site Search","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duracelltomi-google-tag-manager\/google-tag-manager-for-wordpress-115-reflected-cross-site-scripting-via-site-search","description":"The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization in versions up to an including 1.15. The affected file is ~\/public\/frontend.php and this could be exploited by unauthenticated attackers.","date":"2022-05-19"},{"id":"b5384be3-91c0-45e8-ae03-0188be12bc09","name":"Google Tag Manager for WordPress &lt; 1.15.1 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/b5384be3-91c0-45e8-ae03-0188be12bc09","description":"The plugin does not sanitise and escape the s parameter before outputting it back in a page when the search data is included in the data layer (related settings is Basic data &gt; Search data)","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9c900564333fd0a2d802b7d6b4fae8ed28d932616051e8a067d710a9db33c283","name":"GTM4WP &#8211; A Google Tag Manager (GTM) plugin for WordPress [duracelltomi-google-tag-manager] < 1.15.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.15.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-1961","name":"CVE-2022-1961","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-1961","description":"[en] The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the `gtm4wp-options[scroller-contentid]` parameter found in the `~\/public\/frontend.php` file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.15.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.","date":"2022-06-13"},{"id":"183b91fc5bdd99d5db68f607810e1c5bf55e5c5c","name":"WordPress GTM4WP plugin <= 1.15.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duracelltomi-google-tag-manager\/vulnerability\/wordpress-gtm4wp-plugin-1-15-1-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Muhammad Zeeshan (Xib3rR4dAr) in WordPress GTM4WP plugin (versions <= 1.15.1).\nUpdate the WordPress GTM4WP plugin to the latest available version (at least 1.15.2)","date":"2022-05-31"},{"id":"f9f8e84eaa3830c3f97037c34080f44952752c01","name":"Google Tag Manager for WordPress (GTM4WP) <= 1.15.1 - Stored Cross-Site Scripting via Content Element ID","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duracelltomi-google-tag-manager\/google-tag-manager-for-wordpress-gtm4wp-1151-stored-cross-site-scripting-via-content-element-id","description":"The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the `gtm4wp-options[scroller-contentid]` parameter found in the `~\/public\/frontend.php` file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.15.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.","date":"2022-05-31"},{"id":"78f097ff-ac14-4d30-a80f-29709f7d1f69","name":"GTM4WP &lt; 1.15.2 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/78f097ff-ac14-4d30-a80f-29709f7d1f69","description":"The plugin does not properly escape the Content Element ID settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when unfiltered_html is disallowed (for example multisite setups)","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f8b039d04c800fa3067c8557a2940b6f8449d559c98fe16d3447238d61ed4caa","name":"GTM4WP &#8211; A Google Tag Manager (GTM) plugin for WordPress [duracelltomi-google-tag-manager] < 1.15.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.15.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f326749b7d8d446a0858dfe27a5e8abccea1a03b","name":"Google Tag Manager for WordPress <= 1.15 - Cross-Site Scripting via Cloudflare Country Code","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duracelltomi-google-tag-manager\/google-tag-manager-for-wordpress-115-cross-site-scripting-via-cloudflare-country-code","description":"The Google Tag Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $_SERVER['HTTP_CF_IPCOUNTRY'] value in versions up to, and including, 1.15 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2022-05-12"}],"impact":[]},{"uuid":"89dfdeadfee0e066495c3e0a9b22fa3fda97f1935523e930ce44aaea6cf74f10","name":"GTM4WP &#8211; A Google Tag Manager (GTM) plugin for WordPress [duracelltomi-google-tag-manager] < 1.22.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.22.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-16597","name":"CVE-2026-16597","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-16597","description":"[en] The GTM4WP \u2013 A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the GTM4WP WooCommerce order data integration option (GTM4WP_OPTION_INTEGRATE_WCORDERDATA) to be enabled, and is exploited by placing a guest checkout order with a JavaScript payload in a WooCommerce billing field such as the billing first name.","date":"2026-07-29"},{"id":"cb3928d337389ac4f3e7bb734da25fc36ca97116","name":"GTM4WP <= 1.22.3 - Unauthenticated Stored Cross-Site Scripting via WooCommerce Billing Fields","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/duracelltomi-google-tag-manager\/gtm4wp-1223-unauthenticated-stored-cross-site-scripting-via-woocommerce-billing-fields","description":"The GTM4WP \u2013 A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the GTM4WP WooCommerce order data integration option (GTM4WP_OPTION_INTEGRATE_WCORDERDATA) to be enabled, and is exploited by placing a guest checkout order with a JavaScript payload in a WooCommerce billing field such as the billing first name.","date":"2026-07-28"},{"id":"b7e61b89fd0e95100c12a70ab727ebfef3f7eb5a","name":"WordPress Google Tag Manager Plugin <= 1.22.3 is vulnerable to a medium priority Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/duracelltomi-google-tag-manager\/vulnerability\/wordpress-gtm4wp-a-google-tag-manager-gtm-plugin-for-wordpress-plugin-1-22-3-unauthenticated-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Google Tag Manager Plugin <= 1.22.3 is vulnerable to a medium priority Cross Site Scripting (XSS)<\/p><p>Software: Google Tag Manager<\/p><p>Fixed in version 1.22.4 <\/p><p>Affected Version <= 1.22.3<\/p><p>CVE: CVE-2026-16597<\/p>","date":"2026-08-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1785845499"}