CVE-2025-6201

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's conversion-pixel in all versions up to, and including, 1.49.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>The Pixel Manager is the most complete conversion tracking plugin for WooCommerce. Set up Google Ads conversion tracking, Google Analytics GA4 e-commerce tracking, Meta/Facebook Pixel, TikTok Pixel, and more – in minutes, not hours. No coding required.</p> <p>Unlike Google Tag Manager (GTM), which requires significant technical expertise to configure WooCommerce e-commerce tracking correctly, the Pixel Manager provides a turnkey solution with over 12 years of development. It automatically handles edge cases like payment gateway redirects, order duplication prevention, and consent mode – all the things that take hours to get right with manual tag management.</p> <p>🚀 <strong>Endorsed by Google&#8217;s Tag Team</strong></p> <blockquote> <p>This plugin was recommended to us by Google&#8217;s Tag Implementation Team. That should say enough.</p> </blockquote> <p><a href="https://wordpress.org/support/topic/simple-easy-to-use-does-what-it-says-on-the-tin/" rel="ugc">says @dpackert24</a></p> <blockquote> <p>This plugin was demonstrated to me by a Google Tagging Support person. &#8216;nough said 🙂</p> </blockquote> <p><a href="https://wordpress.org/support/topic/simple-functional-free/" rel="ugc">says @galbaras</a></p> <blockquote> <p>We&#8217;re using this for our biggest clients and it&#8217;s working great!</p> </blockquote> <p><a href="https://wordpress.org/support/topic/were-using-this-for-our-biggest-clients-and-its-working-great/" rel="ugc">says @wodobo</a></p> <blockquote> <p>Pixel Manager for WooCommerce is the go-to plugin for both tech wizards and casual users.</p> </blockquote> <p><a href="https://wordpress.org/support/topic/the-go-to-plugin-tracking-everything/" rel="ugc">says @chxz</a></p> <p><strong>What makes the Pixel Manager different?</strong></p> <p>Most WooCommerce tracking plugins only handle the basics: firing a conversion pixel on the thank you page. The Pixel Manager goes much further. It tracks the entire e-commerce customer journey – from product impressions and add-to-cart events through checkout and purchase – across all major advertising and analytics platforms simultaneously. This gives you complete data for conversion optimization, dynamic remarketing audience building, and accurate ROAS reporting.</p> <p>The Pro version adds server-side tracking (Conversion API / CAPI) that sends conversion data directly from your server to advertising platforms. This bypasses browser limitations like ad blockers, Safari ITP cookie restrictions, and network issues – typically recovering up to 30% more conversions that browser-only tracking misses. Our unique Automatic Conversion Recovery (ACR) feature goes even further by automatically identifying and recovering missed conversions nightly.</p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/BW0Tzyu2HaU?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p><strong>Key Benefits</strong></p> <p>&#9989; Easy setup – just enter your tracking IDs and you&#8217;re done.<br /> &#9989; Accurate e-commerce event tracking across all platforms.<br /> &#9989; GDPR and CCPA compliant with Google Consent Mode v2.<br /> &#9989; Works with 15+ consent management platforms out of the box.<br /> &#9989; Lightweight – won&#8217;t slow down your WooCommerce store.<br /> &#9989; Payment Gateway Accuracy Report – diagnose conversion tracking drops.<br /> &#9989; Automatic Conversion Recovery (ACR) – recover lost conversions (Pro).</p> <p><strong>Free Tracking Pixels</strong></p> <ul> <li>Google Ads Pixel – conversion value tracking, dynamic remarketing, cart item data</li> <li>Google Analytics Pixel (GA4) – full Enhanced E-Commerce tracking</li> <li>Meta Ads Pixel (Facebook Pixel) – remarketing events and custom audiences</li> <li>Hotjar Pixel – heatmaps and session recordings</li> </ul> <p><strong>Free Features</strong></p> <ul> <li>Google Tag Gateway for Advertisers – first-party tracking through Google&#8217;s servers</li> <li>Google Consent Mode v2 – full compliance with EU, UK, and US privacy regulations</li> <li>Google Ads Dynamic Remarketing – build audiences based on product interactions</li> <li>Google Ads Cart Item Tracking – feed cart data to Smart Shopping and Performance Max campaigns</li> <li>Google Shopping New Customer Parameter – optimize for new customer acquisition</li> <li>GA4 Enhanced E-Commerce – track product impressions, add to cart, checkout steps, and purchases</li> <li>Meta Remarketing Events – ViewContent, AddToCart, InitiateCheckout, Purchase</li> <li>Basic Order Duplication Prevention – avoid counting the same conversion twice</li> <li>Customizable filters – fine-tune tracking output for your specific setup</li> <li>Lazy-loaded product list support – works with infinite scroll and AJAX product loading</li> <li><a href="https://sweetcode.com/docs/pmw/diagnostics?utm_source=wordpress.org&amp;utm_medium=wpm-plugin-page&amp;utm_campaign=pixel-manager-for-woocommerce-docs&amp;utm_content=payment-gateway-accuracy-report#payment-gateway-tracking-accuracy-report" rel="nofollow ugc">Payment Gateway Accuracy Report</a> – identify which payment gateways cause conversion tracking drops</li> </ul> <p>Have a look at the full feature list over <a href="https://sweetcode.com/docs/pmw/features" rel="nofollow ugc">here</a>.</p> <p><strong>Premium Tracking Pixels</strong></p> <ul> <li>Adroll Ads</li> <li>Contentsquare Statistics</li> <li>CrazyEgg Analytics</li> <li>LinkedIn Ads</li> <li>Microsoft Ads (Bing Ads)</li> <li>Outbrain Ads</li> <li>Pinterest Ads</li> <li>Reddit Ads</li> <li>Snapchat Ads</li> <li>Taboola Ads</li> <li>TikTok Ads</li> <li>X (Twitter) Ads</li> <li>VWO (Visual Website Optimizer) – A/B testing</li> </ul> <p><strong>Premium Features</strong></p> <ul> <li><a href="https://sweetcode.com/docs/pmw/features/acr?utm_source=wordpress.org&amp;utm_medium=wpm-plugin-page&amp;utm_campaign=pixel-manager-for-woocommerce-docs&amp;utm_content=acr" rel="nofollow ugc">Automatic Conversion Recovery (ACR)</a> – automatically recover missed conversions nightly</li> <li>Server-side tracking (CAPI) – Meta, TikTok, Pinterest, Snapchat, Reddit, GA4 Measurement Protocol</li> <li>Advanced Order Duplication Prevention</li> <li>Google Ads Enhanced Conversions – first-party data for improved attribution</li> <li>Google Ads Conversion Adjustments – send refund data back to Google Ads</li> <li>Scroll Tracking – measure how far visitors scroll on your pages</li> <li>Automatic Phone and Link Click Tracking</li> </ul> <p>Have a look at the full feature list over <a href="https://sweetcode.com/docs/pmw/features" rel="nofollow ugc">here</a>.</p> <p><strong>Ready to recover lost conversions and get accurate tracking data?</strong> Visit <a href="https://sweetcode.com" rel="nofollow ugc">sweetcode.com</a> to learn more about the Pro version.</p> <p><strong>Documentation</strong></p> <p>Comprehensive setup guides, troubleshooting, and API references: <a href="https://sweetcode.com/docs/pmw/?utm_source=wordpress.org&amp;utm_medium=wpm-plugin-page&amp;utm_campaign=pixel-manager-for-woocommerce-docs" rel="nofollow ugc">Open the documentation</a></p> <p><strong>News</strong></p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/1_SoAVwU-Mw?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p><strong>Consent Management</strong></p> <p>The Pixel Manager integrates with all major Consent Management Platforms (CMPs) to ensure your tracking pixels respect visitor consent choices. It supports Google Consent Mode v2, including region-specific consent defaults for the EU, UK, and US states with privacy regulations.</p> <p>Compatible consent management plugins:</p> <ul> <li><a href="https://wordpress.org/plugins/beautiful-and-responsive-cookie-consent/" rel="ugc">Beautiful and Responsive Cookie Consent</a></li> <li><a href="https://wordpress.org/plugins/cookiebot/" rel="ugc">Cookiebot</a></li> <li><a href="https://cookieconfirm.com/" rel="nofollow ugc">Cookie Confirm</a></li> <li><a href="https://wordpress.org/plugins/cookie-script-com/" rel="ugc">Cookie Script</a></li> <li><a href="https://wordpress.org/plugins/complianz-gdpr/" rel="ugc">Complianz GDPR/CCPA Cookie Consent</a></li> <li><a href="https://wordpress.org/plugins/cookie-notice/" rel="ugc">Cookie Notice</a></li> <li><a href="https://wordpress.org/plugins/cookie-notice/" rel="ugc">Cookie Notice &amp; Compliance for GDPR / CCPA</a></li> <li><a href="https://wordpress.org/plugins/cookie-law-info/" rel="ugc">Cookie Law Info</a></li> <li><a href="https://wordpress.org/plugins/gdpr-cookie-compliance/" rel="ugc">GDPR Cookie Compliance</a></li> <li><a href="https://wordpress.org/plugins/auto-terms-of-service-and-privacy-policy/" rel="ugc">WP AutoTerms</a></li> <li><a href="https://wordpress.org/plugins/cookiepro/" rel="ugc">CookiePro by OneTrust</a></li> <li><a href="https://wordpress.org/plugins/uk-cookie-consent/" rel="ugc">Termly</a></li> <li><a href="https://wordpress.org/plugins/iubenda-cookie-law-solution/" rel="ugc">Iubenda</a></li> <li><a href="https://wordpress.org/plugins/wp-consent-api/" rel="ugc">WP Consent API</a></li> <li><a href="https://wordpress.org/plugins/gdpr-cookie-consent/" rel="ugc">WP Cookie Consent</a></li> </ul> <p>Please read the following for additional <a href="https://sweetcode.com/docs/pmw/consent-management/platforms?utm_source=wordpress.org&amp;utm_medium=wpm-plugin-page&amp;utm_campaign=pixel-manager-for-woocommerce-docs&amp;utm_content=cookie-consent-plugins" rel="nofollow ugc">setup information</a></p> <p><strong>Requirements</strong></p> <p><a href="https://sweetcode.com/docs/pmw/setup/requirements?utm_source=wordpress.org&amp;utm_medium=wpm-plugin-page&amp;utm_campaign=pixel-manager-for-woocommerce-docs&amp;utm_content=requirements" rel="nofollow ugc">List of requirements</a></p> <p><strong>Security Review</strong></p> <p>Although we follow security best practices, we wanted to ensure that we didn&#8217;t miss anything. So, we had the plugin reviewed by <a href="https://patchstack.com/" rel="nofollow ugc">Patchstack</a>, a cybersecurity company specializing in WordPress security.</p> <p>The summary of their report was: &#8220;We were unable to detect any vulnerabilities that would impact the security status of the plugin in a serious way.&#8221;</p> <p><strong>Managed Vulnerability Disclosure Program</strong></p> <p>We are committed to ensuring the security of our customers and their data. If you believe you have found a security vulnerability in the Pixel Manager for WooCommerce, we encourage you to report it through Patchstack our security partner. Patchstack runs a managed Vulnerability Disclosure Program (mVDP) that helps us receive, triage, and respond to reported vulnerabilities. Patchstack also provides a reward for the responsible disclosure of security vulnerabilities. <a href="https://patchstack.com/database/vdp/woocommerce-google-adwords-conversion-tracking-tag" rel="nofollow ugc">Report a vulnerability</a></p>
WordPress Plugin DirectoryWordPress Plugin Directory
3.45M