A vulnerability marked as problematic has been reported in wedevs StoreGrowth Plugin up to 2.1.0 on WordPress. This issue affects the function wp_localize_script. The manipulation of the argument message_popup leads to cross site scripting.

This vulnerability is traded as CVE-2026-13440. It is possible to initiate the attack remotely. There is no exploit available.