WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Conversios – GA4, Google Ads & Meta Conversion Tracking with Product Feed for WooCommerce

GA4, Google Ads & Meta Pixel conversion tracking plus product feed sync for WooCommerce. Server-side tracking (CAPI) and reports in one plugin.

9Reported vulnerabilities
8.8Highest CVSS score
7.2.23Latest version
10,000+Active installs

What to do now

Update Conversios – GA4, Google Ads & Meta Conversion Tracking with Product Feed for WooCommerce to 7.2.14 or later. 9 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 12, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-1203 High 8.8 0.8% Before 7.0.8 7.0.8 March 13, 2024
CVE-2024-0786 Medium 6.5 0.7% Before 7.0.8 7.0.8 February 28, 2024
CVE-2024-29794 Medium 6.1 0.4% 6.9.1 and earlier 7.0.0 March 25, 2024
CVE-2023-46094 Medium 6.1 0.3% 6.5.3 and earlier 6.5.4 October 17, 2023
CVE-2023-51357 Medium 5.3 0.5% 6.5.0 and earlier 6.5.1 December 26, 2023
CVE-2024-6288 Medium 4.7 0.4% 0 to 7.1.0 (inclusive) 7.1.1 June 28, 2024
CVE-2025-62925 Medium 4.3 0.2% 7.2.13 and earlier 7.2.14 October 5, 2025
CVE-2025-30909 Medium 4.3 0.3% 7.2.3 and earlier 7.2.4 March 27, 2025
CVE-2022-46797 Medium 4.3 0.2% 5.2.3 and earlier 5.2.4 February 6, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.