CVE-2026-1902 | Hammas Calendar Plugin up to 1.5.11 on WordPress Shortcode hp-calendar-manage-redirect apix cross site scripting (EUVD-2026-10097)
A vulnerability, which was classified as problematic, has been found in Hammas Calendar Plugin up to 1.5.11 on WordPress. This affects the function hp-calendar-manage-redirect of the component Shortcode Handler. This manipulation of the argument apix causes cross site scripting.
This vulnerability appears as CVE-2026-1902. The attack may be initiated remotely. There is no available exploit.