{"error":0,"message":null,"data":{"name":"Meta pixel for WordPress","plugin":"official-facebook-pixel","link":"https:\/\/wordpress.org\/plugins\/official-facebook-pixel\/","latest":"1785142380","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"5f53f116a0e0058108540403fdc98e64478a3d1f75a615a5740f6898cd2b9747","name":"Meta pixel for WordPress [official-facebook-pixel] < 3.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24217","name":"CVE-2021-24217","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24217","description":"[en] The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method in the plugin that could be used to achieve remote code execution.","date":"2021-04-12"},{"id":"509f2754-a1a1-4142-9126-ae023a88533a","name":"Facebook for WordPress &lt; 3.0.0 - PHP Object Injection with POP Chain","link":"https:\/\/wpscan.com\/vulnerability\/509f2754-a1a1-4142-9126-ae023a88533a","description":"The run_action function of the plugin deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method in the plugin that could be used to achieve remote code execution.","date":null},{"id":"483455c5ed0fb068fd7a5f1e3518b224bc14b07e","name":"Meta pixel for WordPress <= 2.2.2 - PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/official-facebook-pixel\/meta-pixel-for-wordpress-222-php-object-injection","description":"The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method in the plugin that could be used to achieve remote code execution.","date":"2021-03-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.1","severity":"h","exploitable":"2.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.1","severity":"high","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.2","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}]}},{"uuid":"4e0c97850392e5fb558b2bc5bd2385f4efb5758a2af889c8325a2ed1ab366d3e","name":"Meta pixel for WordPress [official-facebook-pixel] >= 3.0.0 - <= 3.0.3","description":null,"operator":{"min_version":"3.0.0","min_operator":"ge","max_version":"3.0.3","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24218","name":"CVE-2021-24218","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24218","description":"[en] The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF due to a lack of nonce protection. The settings in the saveFbeSettings function had no sanitization allowing for script tags to be saved.","date":"2021-04-12"},{"id":"169d21fc-d191-46ff-82e8-9ac887aed8a4","name":"Facebook for WordPress 3.0.0-3.0.3 - CSRF to Stored XSS and Settings Deletion","link":"https:\/\/wpscan.com\/vulnerability\/169d21fc-d191-46ff-82e8-9ac887aed8a4","description":"The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the plugin were vulnerable to CSRF due to a lack of nonce protection. The settings in the saveFbeSettings function had no sanitization allowing for script tags to be saved.","date":null},{"id":"3c6b872340d4f7114a9b6a240070c73185fe5c00","name":"Facebook for WordPress <= 3.0.3 - Cross-site Request Forgery to Stored Cross-site Scripting and Settings Deletion via wp_ajax_(save|delete)_fbe_settings","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/official-facebook-pixel\/facebook-for-wordpress-303-cross-site-request-forgery-to-stored-cross-site-scripting-and-settings-deletion-via-wp-ajax-savedelete-fbe-settings","description":"The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF due to a lack of nonce protection. The settings in the saveFbeSettings function had no sanitization allowing for script tags to be saved.","date":"2021-03-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"f217dbc5cf8c7ab19476eedd629d90679403b4a8a92c61991e7a19a12dd45f59","name":"Meta pixel for WordPress [official-facebook-pixel] < 3.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8d827620beb3f519da20462dbab411bcc0594608","name":"WordPress Facebook for WordPress plugin <= 2.2.2 - PHP Object Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/official-facebook-pixel\/vulnerability\/wordpress-facebook-for-wordpress-plugin-2-2-2-php-object-injection-vulnerability","description":"PHP Object Injection vulnerability discovered by WordFence in WordPress Facebook for WordPress plugin (versions <= 2.2.2).","date":"2021-03-25"}],"impact":[]},{"uuid":"3643b9d5bbd140845e312c759b3055fe6687a6185d6097f88c990661416c6c10","name":"Meta pixel for WordPress [official-facebook-pixel] >= 3.0.0 - <= 3.0.3","description":null,"operator":{"min_version":"3.0.0","min_operator":"ge","max_version":"3.0.3","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"049dc2c0aa01b5143007870c859ad6816aac534b","name":"WordPress Facebook for WordPress plugin <= 3.0.3 - Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/official-facebook-pixel\/vulnerability\/wordpress-facebook-for-wordpress-plugin-3-0-3-cross-site-request-forgery-csrf-leading-to-stored-cross-site-scripting-xss-vulnerability","description":"Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability discovered by WordFence in WordPress Facebook for WordPress plugin (versions 3.0.0 \u2013 3.0.3).","date":"2021-03-25"}],"impact":[]},{"uuid":"e1a11576403d0f22ec363ad59c4e42c46c0155b4fda213e7d1e3012b14a3cf38","name":"Meta pixel for WordPress [official-facebook-pixel] < 5.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-66705","name":"CVE-2026-66705","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-66705","description":"[en] Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.","date":"2026-08-06"},{"id":"0203824d255ed0f8bc212975943eadbeeb55861c","name":"WordPress Facebook for WordPress Plugin <= 5.2.1 is vulnerable to a medium priority Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/official-facebook-pixel\/vulnerability\/wordpress-facebook-for-wordpress-plugin-5-2-1-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Facebook for WordPress Plugin <= 5.2.1 is vulnerable to a medium priority Cross Site Scripting (XSS)<\/p><p>Software: Facebook for WordPress<\/p><p>Fixed in version 5.2.2 <\/p><p>Affected Version <= 5.2.1<\/p><p>CVE: CVE-2026-66705<\/p>","date":"2026-07-31"},{"id":"24dc1cc4a66562cc1a110184367e394ce614dd2c","name":"Meta pixel for WordPress <= 5.2.1 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/b0c12678-1d91-4916-aa11-20292d9e384b","description":"The Meta pixel for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-31"},{"id":"1f469207c535a0fac422345eec91a8b8c667f01f","name":"Meta pixel for WordPress <= 5.2.1 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/official-facebook-pixel\/meta-pixel-for-wordpress-521-unauthenticated-stored-cross-site-scripting","description":"The Meta pixel for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2021-03-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1785910672"}