CVE-2026-1905 | Sphere Manager Plugin up to 1.0.2 on WordPress Shortcode show_sphere_image width cross site scripting
A vulnerability was found in Sphere Manager Plugin up to 1.0.2 on WordPress. It has been classified as problematic. Affected by this issue is the function show_sphere_image of the component Shortcode Handler. This manipulation of the argument width causes cross site scripting.
This vulnerability appears as CVE-2026-1905. The attack may be initiated remotely. There is no available exploit.