CVE-2026-2504 | Dealia Plugin up to 1.0.6 on WordPress AJAX PostsController.php wp_localize_script authorization
A vulnerability categorized as problematic has been discovered in Dealia Plugin up to 1.0.6 on WordPress. This issue affects the function wp_localize_script of the file PostsController.php of the component AJAX Handler. Such manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-2504. The attack can be launched remotely. No exploit exists.