CVE-2026-28172 HIGH

CVE-2026-28172: WordPress Tracking Code Manager plugin <= 2.6.0 - CSRF to Stored XSS vulnerability

Vendor Data443 Risk Mitigation, Inc.
Product Tracking Code Manager
Weakness CWE-352 · CSRF
Published August 6, 2026
Last update August 6, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.

Explanation of Vulnerability in Simple Terms

02Summary

Tracking Code Manager versions up to 2.6.0 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to perform unauthorized actions on behalf of site administrators. An attacker can craft a malicious link or page that, when visited by an authenticated admin, executes unwanted changes to the plugin's settings or data. The vulnerability requires user interaction and affects confidentiality, integrity, and availability of the site.

What an attacker can do

03Attacker Capabilities

Perform unauthorized actions on the site by tricking an admin into visiting a malicious page.

Potential impact on your site

04Site Impact

Attackers can modify plugin settings, inject tracking code, or alter site configuration without your knowledge or consent.

Conditions required to exploit

05Prerequisites

Admin must visit attacker-controlled page while logged into WordPress; no special privileges required from attacker.

Key dates

06Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated

Related vulnerabilities

08Related CVE