CVE-2026-1804 | WDES Responsive Popup Plugin up to 1.3.6 on WordPress Shortcode wdes-popup-title attr cross site scripting
A vulnerability was found in WDES Responsive Popup Plugin up to 1.3.6 on WordPress. It has been classified as problematic. Impacted is the function wdes-popup-title of the component Shortcode Handler. This manipulation of the argument attr causes cross site scripting.
This vulnerability is tracked as CVE-2026-1804. The attack is possible to be carried out remotely. No exploit exists.