Microsoft Advertising Universal Event Tracking (UET)
Microsoft Advertising Universal Event Tracking (UET) has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 5.5 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Microsoft Advertising Universal Event Tracking (UET) has a vendor fix available, so running the current release closes it.
All of these findings were reported by Chowdhury Faizal Ahammed. Microsoft Advertising Universal Event Tracking (UET) is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2022-2170Microsoft Advertising Universal Event Tracking (UET) <= 1.0.3 - Authenticated Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Microsoft Advertising Universal Event Tracking (UET)
Author
Microsoft
This plugin will install Microsoft Advertising Universal Event Tracking (UET) tag for your page so you can use powerful Microsoft Advertising features such as conversion tracking and audience targeting. UET tag records what customers do on your website and sends that information to Microsoft Advertising. UET is a prerequisite for conversion tracking, remarketing in paid search, and automated bidding bid strategies. These features can help you better understand your customer’s journey from when they click on your ad to when they convert on your website. You can use this to create more relevant ad campaigns for your business and to target the right audience for your campaigns. You can learn more here. Additional Information Microsoft Open Source Code of Conduct Trademark Notice Security Reporting Instructions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C