A vulnerability marked as problematic has been reported in wpxpo WowStore Plugin up to 4.4.24 on WordPress. This affects the function
render_callback of the component Block Attribute. Performing a manipulation of the argument filterMobileText results in cross site scripting.
This vulnerability is known as CVE-2026-17161. Remote exploitation of the attack is possible. No exploit is available.