PT-2026-8038 · WordPress · Pixelyoursite Pro

Os

+1

·

Published

2026-02-13

·

Updated

2026-02-14

·

CVE-2026-1844

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PixelYourSite PRO plugin for WordPress versions prior to 12.4.0.3
Description The PixelYourSite PRO plugin for WordPress is susceptible to Stored Cross-Site Scripting. This is due to insufficient input sanitization and output escaping related to the pysTrafficSource parameter and the pys landing page parameter. An unauthenticated attacker can inject arbitrary web scripts into pages. These scripts will execute when a user accesses the injected page.
Recommendations Update the PixelYourSite PRO plugin to version 12.4.0.3 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-1844

Affected Products

Pixelyoursite Pro