WordPress · Tag Groups · CVE-2026-9833
**Name of the Vulnerable Software and Affected Versions**
Tag Groups versions prior to 2.2.0
**Description**
An issue exists where the plugin fails to properly escape an AJAX parameter before reflecting it in the response body served with an HTML content type. This allows unauthenticated attackers to execute arbitrary JavaScript in the browser of a logged-in user who possesses the `edit pages` capability (Editor or higher) if they are tricked into following a crafted link.
**Recommendations**
Update to version 2.2.0 or later.