
CVE-2026-2420 The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.0.6 due to i… https://www.cve.org/CVERecord?id=CVE-2026-2420
Post summary
The LotekMedia Popup Form plugin for WordPress is disclosed to have a stored XSS vulnerability in all versions up to 1.0.6, but no PoC, patch, or evidence of active exploitation is mentioned.

