The Hammas Calendar plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability. The flaw is present in versions up to 1.5.11, allowing authenticated users with Contributor-level access and above to inject malicious scripts through the 'apix' parameter.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.