Description
WordPress Plugin Pixel Manager for WooCommerce-Track Google Analytics, Google Ads, TikTok and more is prone to a supply chain attack because of the Polyfill JavaScript library used. The ownership of the library was taken over by malicious threat actors that used the service to redirect victims to malicious websites. WordPress Plugin Pixel Manager for WooCommerce-Track Google Analytics, Google Ads, TikTok and more version 1.43.3 is affected; prior versions may also be affected.
Remediation
Update to plugin version 1.43.4 or latest
References
Related Vulnerabilities
MySQL CVE-2020-14844 Vulnerability (CVE-2020-14844)
WordPress Plugin ActiveCampaign-Forms, Site Tracking, Live Chat Cross-Site Request Forgery (8.0.1)
WordPress Plugin AceIDE Local File Inclusion (2.6.2)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1725)