Extension WordPress
Vulnérabilités Conversios – GA4, Google Ads & Meta Conversion Tracking with Product Feed for WooCommerce
Cette page rassemble les failles publiées pour Conversios – GA4, Google Ads & Meta Conversion Tracking with Product Feed for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Conversios – GA4, Google Ads & Meta Conversion Tracking with Product Feed for WooCommerce
10 fiches
Conversios.io <= 7.2.13 – Missing Authorization
The Conversios.io plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.2.13. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-7.2.13
7.2.14
05/10/2025
Conversios.io <= 7.2.3 – Missing Authorization
The Conversios: Google Analytics GA4, Google Ads, GTM & Multiple Pixel Tracking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.2.3. This…
*-7.2.3
7.2.4
27/03/2025
Conversios.io – All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce <= 7.1.0 – Reflected Cross-Site Scripting
The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tiktok_user_id’ parameter in all versions up to, and including, 7.1.0…
*-7.1.0
7.1.1
27/06/2024
Conversios.io <= 6.9.1 – Reflected Cross-Site Scripting
The Conversios.io plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 6.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-6.9.1
7.0.0
25/03/2024
Conversios <= 7.0.7 – Authenticated (Subscriber+) SQL Injection via ee_syncProductCategory
The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ee_syncProductCategory function using the parameters conditionData, valueData, productArray, exclude and…
*-7.0.7
7.0.8
27/02/2024
Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce <= 7.0.7 – Authenticated (Subscriber+) SQL Injection
The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'valueData' parameter in all versions up to, and including, 7.0.7 due…
*-7.0.7
7.0.8
27/02/2024
Conversios.io <= 6.5.0 – Missing Authorization
The Conversios.io plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the conversios-productsync/v1/cron-productsync REST API endpoint in versions up to, and including, 6.5.0. This makes it possible for unauthenticated attackers…
*-6.5.0
6.5.1
26/12/2023
Conversios.io <= 6.5.3 – Reflected Cross-Site Scripting
The Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 6.5.3 due…
*-6.5.3
6.5.4
17/10/2023
All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce <= 5.2.3 – Cross-Site Request Forgery
The All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.3. This is due to missing or incorrect nonce validation on multiple…
*-5.2.3
5.2.4
06/02/2023
Conversios.io – Google Analytics and Google Shopping plugin for WooCommerce <= 4.6.1 Authenticated SQL Injection
The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action before using it in a SQL statement, allowing any authenticated user to perform SQL injection attacks.
[*, 4.6.2)
4.6.2
01/02/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.