What is CVE-2026-13604?
The Pixelavo WordPress plugin (versions before 1.5.4) registers an unauthenticated AJAX action that can be exploited using a publicly accessible nonce. This allows attackers to send arbitrary event data to the Facebook Conversions API using the administrator's stored access token. Immediate update to the latest version is recommended.
Azərbaycanca: Pixelavo WordPress plaginində (1.5.4-dən əvvəlki versiyalarda) autentifikasiya olunmamış AJAX əməliyyatı aşkarlanıb. Bu qüsur, hücumçulara admin səviyyəli Facebook Conversions API tokenindən istifadə edərək yalan məlumat göndərməyə imkan verir. Plagini dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What vulnerable action can be performed through the Pixelavo plugin?
In versions before 1.5.4, the plugin registers an unauthenticated AJAX action that allows attackers to send fake data using the admin-level Facebook Conversions API token.
What is the recommended security measure for the Pixelavo plugin?
Immediate update to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.