CVE-2026-14315
Early awareness chatter, no PoC or KEV listing; likely pre-coordinated disclosure window.
What: Unauthenticated AJAX action in Pixel Tag Manager for WooCommerce plugin allows forged e-commerce conversion event submission to advertising APIs using stored site credentials.
Why it matters: Published today; no CVSS/EPSS assigned yet, not KEV-listed. Social chatter in Hebrew, Chinese, and Russian appears to be early awareness posts rather than exploitation reports or PoC drops. No vendor advisory urgency signals visible in supplied posts.
Where it's seen: Multilingual social media posts on Bluesky driving initial awareness; no public PoC, no defender triage questions, no vendor patch advisory metadata yet.
RISK: MODERATE — Unauthenticated API abuse, but limited scope to ad conversion fraud and dependent on site configuration.
Description
The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials.