CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-13604

unknowncovered by 1 sourcefirst seen 2026-08-01
The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access token. This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.

⚡ Watch CVE-2026-13604

Get an email if CVE-2026-13604 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-13604

CVE.org record

Embed the live status

CVE-2026-13604 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-13604 status](https://www.csirts.com/badge/CVE-2026-13604)](https://www.csirts.com/cve/CVE-2026-13604)