Cross-Site Scripting
4 records33.3%First: 2018. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 12 vulnerability records associated with PixelYourSite – Your smart PIXEL (TAG) & API Manager, published between 2018 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2018 | 1 | |
| 2023 | 2 | |
| 2024 | 2 | |
| 2025 | 5 | |
| 2026 | 2 |
| Severity | Records | Share |
|---|---|---|
| High | 2 | 16.7% |
| Medium | 10 | 83.3% |
First: 2018. Latest: 2026.
First: 2023. Latest: 2025.
First: 2025. Latest: 2025.
First: 2025. Latest: 2026.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
11.2.211.2.0.111.1.5.111.1.211.1.310.1.1.210.0.29.7.29.6.29.3.79.3.15.3.0Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-11.2.1 | PixelYourSite <= 11.2.1 - Unauthenticated Sensitive Information Exposure via Order-Received Endpoint Missing Key Validation | July 31, 2026 | 11.2.2 | Medium |
*-11.2.0 | PixelYourSite <= 11.2.0 - Unauthenticated Stored Cross-Site Scripting | February 13, 2026 | 11.2.0.1 | High |
*-11.1.5 | PixelYourSite <= 11.1.5 - Sensitive Information Exposure via Log File | December 29, 2025 | 11.1.5.1 | Medium |
[*, 11.1.2) | PixelYourSite – Your smart PIXEL (TAG) Manager < 11.1.2 - Authenticated (Administrator+) Local File Inclusion | October 24, 2025 | 11.1.2 | Medium |
*-11.1.2 | PixelYourSite <= 11.1.2 – Cross-Site Request Forgery to GDPR Options Modification | October 21, 2025 | 11.1.3 | Medium |
10.1.1.1 | PixelYourSite – Your smart PIXEL (TAG) & API Manager <= 10.1.1.1 - Unauthenticated PHP Object Injection | February 28, 2025 | 10.1.1.2 | High |
*-10.0.1.2 | PixelYourSite – Your smart PIXEL (TAG) Manager <= 10.0.1.2 - Cross-Site Request Forgery | January 6, 2025 | 10.0.2 | Medium |
*-9.7.1 | PixelYourSite – Your smart PIXEL (TAG) & API Manager <= 9.7.1 and PixelYourSite PRO <= 10.4.2 - Unauthenticated Information Exposure and Log Deletion | September 3, 2024 | 9.7.2 | Medium |
*-9.6.1.1 | PixelYourSite – Your smart PIXEL (TAG) Manager <= 9.6.1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting | June 28, 2024 | 9.6.2 | Medium |
*-9.3.6 | PixelYourSite <= 9.3.6 and PixelYourSite Pro <= 9.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting | May 16, 2023 | 9.3.7 | Medium |
*-9.3.0 | PixelYourSite <= 9.3.0 - Cross-Site Request Forgery | January 20, 2023 | 9.3.1 | Medium |
[*, 5.3.0) | PixelYourSite <= 5.2.1 - Reflected Cross-Site Scripting | April 27, 2018 | 5.3.0 | Medium |
Selected source records
Published: July 31, 2026
Published: February 13, 2026
Published: December 29, 2025
Published: October 24, 2025
Published: October 21, 2025
Published: February 28, 2025
Published: January 6, 2025
Published: September 3, 2024
Published: February 28, 2025
Published: February 13, 2026
Published: October 24, 2025
Published: September 3, 2024
Published: April 27, 2018
Published: December 29, 2025
Published: July 31, 2026
Published: May 16, 2023
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.