CVE-2026-13604

MEDIUM CVSS 3.1: 5.3 EPSS 0.17%
Updated Aug 26, 2026
Facebook
Parameter Value
CVSS 5.3 (MEDIUM)
Affected Versions before 1.5.4
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Facebook
Public PoC No

The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access token. This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1