Description
WordPress Plugin Pixel Manager for WooCommerce-Track Google Analytics, Google Ads, TikTok and more is prone to a supply chain attack because of the Polyfill JavaScript library used. The ownership of the library was taken over by malicious threat actors that used the service to redirect victims to malicious websites. WordPress Plugin Pixel Manager for WooCommerce-Track Google Analytics, Google Ads, TikTok and more version 1.43.3 is affected; prior versions may also be affected.
Remediation
Update to plugin version 1.43.4 or latest
References
Related Vulnerabilities
SharePoint Untrusted Pointer Dereference Vulnerability (CVE-2026-40367)
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-15929)
Next.js Uncontrolled Resource Consumption Vulnerability (CVE-2026-27980)
WordPress Plugin Gantry 4 Framework Cross-Site Scripting (4.1.5)