CVE-2026-2420 | LotekMedia Popup Form Plugin up to 1.0.6 on WordPress Setting cross site scripting (EUVD-2026-10136)
A vulnerability was found in LotekMedia Popup Form Plugin up to 1.0.6 on WordPress. It has been classified as problematic. The impacted element is an unknown function of the component Setting Handler. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2026-2420. The attack may be initiated remotely. There is no available exploit.