The Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin for WordPress has a security vulnerability, which means that anyone can inject malicious code (like web scripts) into a website if they can get someone to click on a link. This vulnerability affects all versions of the plugin up to and including 6.5.3 and is caused by the plugin not properly sanitizing and escaping user inputs.