What is CVE-2026-13440?
A Stored Cross-Site Scripting vulnerability in the StoreGrowth plugin for WordPress allows authenticated users to inject scripts via the 'message_popup' parameter. All versions up to 2.1.0 are affected due to insufficient input sanitization, requiring immediate update.
Azərbaycanca: WordPress üçün StoreGrowth plaginində saxlanılan Stored XSS zəifliyi aşkarlanıb. Bu boşluq 'message_popup' parametri vasitəsilə təsdiqlənmiş istifadəçilərə script inyeksiya etməyə imkan verir. Plaginin 2.1.0 və aşağı versiyaları təsirlənir, inzibatçılar dərhal yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by the CVE-2026-13440 vulnerability and what versions are impacted?
This vulnerability was discovered in the StoreGrowth plugin. All versions up to 2.1.0 are affected.
How is the CVE-2026-13440 vulnerability exploited?
Authenticated users can perform a Stored XSS attack via the 'message_popup' parameter, which allows script injection.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.