A vulnerability, which was classified as problematic, was found in PixelYourSite Plugin and PixelYourSite Pro Plugin up to 11.2.1 on WordPress. The affected element is the function getWooPurchaseEventParams of the component Purchase. Such manipulation leads to information disclosure.

This vulnerability is documented as CVE-2026-18059. The attack can be executed remotely. There is not any exploit available.