A vulnerability marked as problematic has been reported in wedevs StoreGrowth Plugin up to 2.1.0 on WordPress. This issue affects the function
wp_localize_script. The manipulation of the argument message_popup leads to cross site scripting.
This vulnerability is traded as CVE-2026-13440. It is possible to initiate the attack remotely. There is no exploit available.