What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in קידום ובניית אתרים add custom google tag manager add-custom-google-tag-manager allows Stored XSS.This issue affects add custom google tag manager: from n/a through <= 1.0.3.
Explanation of Vulnerability in Simple Terms
02Summary
A cross-site request forgery (CSRF) vulnerability in Add Custom Google Tag Manager versions 1.0.3 and earlier allows an attacker to perform unauthorized actions on behalf of a site administrator. The vulnerability requires the admin to visit a malicious page while logged in. An attacker can modify plugin settings or inject malicious tracking code. Update to a version newer than 1.0.3.
What an attacker can do
03Attacker Capabilities
Perform unauthorized actions on the site (modify settings, inject tracking code) by tricking an admin into visiting a malicious page.
Potential impact on your site
04Site Impact
An attacker can alter your Google Tag Manager configuration or inject malicious code without your knowledge if you click a malicious link while logged in.
Conditions required to exploit
05Prerequisites
Site admin must be logged in and visit an attacker-controlled page; no special privileges or direct site access required.
Key dates
06Disclosure timeline
January 16, 2025
CVE published
April 28, 2026
Record updated