What is CVE-2026-14315?
CVE-2026-14315 is an authorization flaw in the Pixel Tag Manager for WooCommerce WordPress plugin before version 2.2.1, affecting an AJAX action. It allows unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs. Update the plugin to version 2.2.1 or later.
Azərbaycanca: CVE-2026-14315, WooCommerce üçün Pixel Tag Manager plaginində 2.2.1-dən əvvəlki versiyalarda bir AJAX əməliyyatında avtorizasiya çatışmazlığıdır. Bu, autentifikasiya olunmamış istifadəçilərə saytın konfiqurasiya olunmuş reklam konversiya API-lərinə saxta e-ticarət konversiya hadisələri göndərməyə imkan verir. Plagini ən azı 2.2.1 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin is affected by CVE-2026-14315?
CVE-2026-14315 affects the Pixel Tag Manager for WooCommerce plugin versions prior to 2.2.1.
What does CVE-2026-14315 allow unauthenticated users to do?
It allows unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.