CyberRota Analysis
AI-GeneratedThe Pixelavo WordPress plugin prior to version 1.5.4 is vulnerable due to an unauthenticated AJAX action that allows attackers to exploit a publicly accessible nonce, enabling them to send arbitrary event data to the Facebook Conversions API using the administrator's access token. This can lead to unauthorized manipulation of conversion events and potential exhaustion of the API quota for the administrator's Facebook ads account. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access token. This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.