Description
WordPress Plugin Pixel Manager for WooCommerce-Track Google Analytics, Google Ads, TikTok and more is prone to a supply chain attack because of the Polyfill JavaScript library used. The ownership of the library was taken over by malicious threat actors that used the service to redirect victims to malicious websites. WordPress Plugin Pixel Manager for WooCommerce-Track Google Analytics, Google Ads, TikTok and more version 1.43.3 is affected; prior versions may also be affected.
Remediation
Update to plugin version 1.43.4 or latest
References
Related Vulnerabilities
WordPress Plugin Enable Media Replace Directory Traversal (3.6.3)
WordPress Plugin Duplicate Page Multiple Vulnerabilities (2.3)
WordPress Plugin Juiz Social Post Sharer Multiple Cross-Site Scripting Vulnerabilities (1.3.3.7)
WordPress Plugin My Link Order Cross-Site Scripting (4.3)
MediaWiki Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1190)