Description
WordPress Plugin Pixel Manager for WooCommerce-Track Google Analytics, Google Ads, TikTok and more is prone to a supply chain attack because of the Polyfill JavaScript library used. The ownership of the library was taken over by malicious threat actors that used the service to redirect victims to malicious websites. WordPress Plugin Pixel Manager for WooCommerce-Track Google Analytics, Google Ads, TikTok and more version 1.43.3 is affected; prior versions may also be affected.
Remediation
Update to plugin version 1.43.4 or latest
References
Related Vulnerabilities
IBM RTC CVE-2018-1694 Vulnerability (CVE-2018-1694)
WordPress Plugin Mitsol Social Post Feed Cross-Site Scripting (1.10)
Drupal Core 9.0.x Multiple Cross-Site Scripting Vulnerabilities (9.0.0 - 9.0.5)
Apache HTTP Server Incorrect Calculation of Buffer Size Vulnerability (CVE-2004-0940)
WordPress Plugin Elementor Website Builder Cross-Site Scripting (3.4.7)