CVE-2026-1826 | OpenPOS Lite Plugin up to 3.0 on WordPress Shortcode width cross site scripting
A vulnerability marked as problematic has been reported in OpenPOS Lite Plugin up to 3.0 on WordPress. This affects an unknown function of the component Shortcode Handler. The manipulation of the argument width leads to cross site scripting.
This vulnerability is traded as CVE-2026-1826. It is possible to initiate the attack remotely. There is no exploit available.