A vulnerability was found in Tag Groups Plugin up to 2.1.x on WordPress and classified as problematic. The impacted element is an unknown function of the component Ajax. Such manipulation leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-9833. The attack can be launched remotely. No exploit exists.