
CVE-2026-1905 The Sphere Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in the 'show_sphere_image' shortcode in all versions up t… https://www.cve.org/CVERecord?id=CVE-2026-1905
Post summary
The post announces a stored XSS vulnerability in the Sphere Manager WordPress plugin, providing technical details but no PoC, exploit code, active exploitation evidence, or patch information.

