## **🔍 What Happened**

A security issue was identified in the **Metasync plugin's server-side rendering (SSR) output**. In affected cases, malicious content — including scripts disguised as Google Tag Manager (GTM) — appeared in a site's live HTML output while the Metasync plugin was active, and disappeared when the plugin was deactivated.

This issue was **not caused by your configuration or content**. It originates from how the plugin constructs and renders output on the server side. Our engineering team is aware of the issue and is actively working on a fix.

## **⚠️ Who Is Affected**

- WordPress sites running the Metasync plugin with server-side rendering enabled
- Sites where injected output appeared only when the Metasync plugin was active — and disappeared when it was deactivated

If your site showed a suspicious GTM-like script in its HTML source **exclusively while Metasync was active**, this vulnerability is the most likely cause.

## **🛠️ What Is Being Done**

Our engineering team has confirmed the issue and a fix is in active development. We will update this article as fixes are released. Watch your platform notifications for plugin update announcements.

## **✅ Immediate Steps to Take**

1. **Deactivate the Metasync plugin** temporarily if you have not already done so. This stops the injection vector while the patched version is being released.
2. **Scan your site's live HTML source** for any unexpected `<script>` tags, especially those referencing GTM-like IDs or external domains you do not recognise.
3. **Check your Google Tag Manager account** to confirm all tags present on your site were added by your team.
4. **Review your server and CMS access logs** for the period when the plugin was active to identify any unusual activity.
5. **Install the updated version of the Metasync plugin** as soon as it is available and announced via platform notifications.

## **📋 When Escalating to Support**

Because this issue requires a backend investigation, please have the following ready when you contact our team:

- Your WordPress site URL
- The exact script or code snippet you observed in your HTML source
- The date and time range when the injection was first noticed
- Confirmation of whether deactivating the Metasync plugin removed the injected content

If you need further assistance, open the chat widget in the bottom-right corner of the platform and type **human teammate** to be connected with a member of our team.