Shapedplugin
Shapedplugin Location Weather: vulnerabilidades y CVE
Shapedplugin Location Weather tiene 3 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE3
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-66433 | Media (6.5) | 0.22% | — | 27 jul 2026 | Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions. |
| CVE-2026-7249 | Media (4.3) | 0.35% | — | 22 may 2026 | The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the `splw_update_block_options()` and `lwp_clean_weather_transients()` functions in all… |
| CVE-2023-0360 | Media (5.4) | 0.54% | — | 13 feb 2023 | The Location Weather WordPress plugin before 1.3.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor… |