Conversion Tracking for WooCommerce
Conversion Tracking for WooCommerce has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2024; all 5 are fixed as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2024 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 3 of the records (60%). Other recurring categories include Cross-Site Request Forgery (CSRF), Cross-Site Scripting.
Every one of the 5 issues recorded for Conversion Tracking for WooCommerce has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by Abdi Pranata. Conversion Tracking for WooCommerce is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
WooCommerce Conversion Tracking <= 2.0.4 - Cross-Site Request Forgery and Cross-Site Scripting
Read the full analysisVulnerability Records
Conversion Tracking for WooCommerce
Author
weDevs
woocommerceWhen you are integrating any advertising campaigns, they provide various tracking codes (mainly JavaScript) to insert them various pages of your site so that it can track how the conversion is happening. This plugin inserts those codes on WooCommerce cart page, checkout success page and after user registration. So you can track who are adding your products to cart, who are buying them and who are registering to your site. Supported Integrations Facebook Twitter Google Adwords Custom Tracking Pro Features More Facebook Events Multiple Facebook Pixels Facebook Product Catalog Perfect Audience Bing Ads More Twitter and Google Adwords Events Get Pro Version Videos All Videos Contribute Github Author Tareq Hasan Privacy Policy woocommerce-conversion-tracking uses Appsero SDK to collect some telemetry data upon user’s confirmation. This helps us to troubleshoot problems faster & make product improvements. Appsero SDK does not gather any data by default. The SDK only starts gathering basic telemetry data when a user allows it via the admin notice. We collect the data to ensure great user experience for all our users. Integrating Appsero SDK DOES NOT IMMEDIATELY start gathering data, without confirmation from users in any case. Learn more how Appsero collects and uses this data. Additionally, read weDevs privacy policy for more.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C