A vulnerability identified as problematic has been detected in Hostinger Reach Plugin up to 1.3.8 on WordPress. Affected is the function handle_ajax_action . This manipulation causes missing authorization. This vulnerability is registered as CVE-2026-2515 . Remote exploitation of the attack is possible. No exploit is available.