A vulnerability identified as critical has been detected in wedevs StoreGrowth Plugin up to 2.1.0 on WordPress. This affects the function
wp_localize_script of the component BoGo Module. Performing a manipulation of the argument ajd_protected results in authorization bypass.
This vulnerability is reported as CVE-2026-15411. The attack is possible to be carried out remotely. No exploit exists.