What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager pixelyoursite allows Cross Site Request Forgery.This issue affects PixelYourSite – Your smart PIXEL (TAG) Manager: from n/a through <= 10.0.1.2.
Explanation of Vulnerability in Simple Terms
02Summary
PixelYourSite versions up to 10.0.1.2 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to perform unwanted actions on behalf of site administrators. An attacker can craft a malicious link or page that, when visited by an admin, triggers unintended changes to site settings or data. The vulnerability requires user interaction—the admin must click the link or visit the attacker's page—but no authentication bypass is needed since the admin is already logged in.
What an attacker can do
03Attacker Capabilities
Trick a logged-in admin into performing unwanted actions like changing plugin settings or modifying site configuration.
Potential impact on your site
04Site Impact
Attackers can alter PixelYourSite settings or configuration without your knowledge if an admin visits a compromised page.
Conditions required to exploit
05Prerequisites
Admin must visit a malicious link or page while logged into the site.
Key dates
06Disclosure timeline
January 7, 2025
CVE published
April 28, 2026
Record updated