A vulnerability identified as critical has been detected in wedevs StoreGrowth Plugin up to 2.1.0 on WordPress. This affects the function wp_localize_script of the component BoGo Module. Performing a manipulation of the argument ajd_protected results in authorization bypass.

This vulnerability is reported as CVE-2026-15411. The attack is possible to be carried out remotely. No exploit exists.