🛡️ Metasync Plugin Script Injection Security Issue

Camilo Aponte

Camilo Aponte

Last updated on Sep 30, 2026

🔍 What Happened

A security issue was identified in the Metasync plugin's server-side rendering (SSR) output. In affected cases, malicious content — including scripts disguised as Google Tag Manager (GTM) — appeared in a site's live HTML output while the Metasync plugin was active, and disappeared when the plugin was deactivated.

This issue was not caused by your configuration or content. It originates from how the plugin constructs and renders output on the server side. Our engineering team is aware of the issue and is actively working on a fix.

⚠️ Who Is Affected

  • WordPress sites running the Metasync plugin with server-side rendering enabled
  • Sites where injected output appeared only when the Metasync plugin was active — and disappeared when it was deactivated

If your site showed a suspicious GTM-like script in its HTML source exclusively while Metasync was active, this vulnerability is the most likely cause.

🛠️ What Is Being Done

Our engineering team has confirmed the issue and a fix is in active development. We will update this article as fixes are released. Watch your platform notifications for plugin update announcements.

✅ Immediate Steps to Take

  1. Deactivate the Metasync plugin temporarily if you have not already done so. This stops the injection vector while the patched version is being released.
  2. Scan your site's live HTML source for any unexpected <script> tags, especially those referencing GTM-like IDs or external domains you do not recognise.
  3. Check your Google Tag Manager account to confirm all tags present on your site were added by your team.
  4. Review your server and CMS access logs for the period when the plugin was active to identify any unusual activity.
  5. Install the updated version of the Metasync plugin as soon as it is available and announced via platform notifications.

📋 When Escalating to Support

Because this issue requires a backend investigation, please have the following ready when you contact our team:

  • Your WordPress site URL
  • The exact script or code snippet you observed in your HTML source
  • The date and time range when the injection was first noticed
  • Confirmation of whether deactivating the Metasync plugin removed the injected content

If you need further assistance, open the chat widget in the bottom-right corner of the platform and type human teammate to be connected with a member of our team.