CVE-2026-1804 | WDES Responsive Popup Plugin up to 1.3.6 on WordPress Shortcode wdes-popup-title attr cross site scripting
A vulnerability was found in WDES Responsive Popup Plugin up to 1.3.6 on WordPress. It has been declared as problematic. The affected element is the function wdes-popup-title of the component Shortcode Handler. Such manipulation of the argument attr leads to cross site scripting.
This vulnerability is listed as CVE-2026-1804. The attack may be performed from remote. There is no available exploit.