VYPR

Pixelavo

by WordPress

CVEs (1)

  • CVE-2026-13604Aug 1, 2026
    risk 0.00cvss epss 0.00

    The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access…