plugin

Awesome Weather Vulnerabilities

4 known security issues reported for the Awesome Weather WordPress plugin. Most recent disclosed Sep 14, 2023.

2 medium

Running Awesome Weather on your site? Check whether your installed version is affected.

Scan your site free

Awesome Weather Widget [awesome-weather] <= 3.0.2 (unfixed)

unknown

[en] The Awesome Weather Widget for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' shortcode in versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...

Affected:
up to 3.0.2
Fix:
No patched version reported
Disclosed:
Sep 14, 2023

CVE-2023-4944 on NVD →

Awesome Weather Widget <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Awesome Weather Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' shortcode in versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor...

CVSS:
6.4
Affected:
up to 3.0.2
Fix:
No patched version reported
Disclosed:
Sep 13, 2023

CVE-2023-4944 on NVD →

Awesome Weather Widget [awesome-weather] <= 3.0.2 (unfixed + closed)

unknown

[en] The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refresh AJAX action, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability.

Affected:
up to 3.0.2
Fix:
No patched version reported
Disclosed:
Aug 2, 2021

CVE-2021-24474 on NVD →

Awesome Weather Widget <= 3.0.2 - Reflected Cross-site Scripting via id Parameter

medium

The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refresh AJAX action, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability.

CVSS:
6.1
Affected:
up to 3.0.2
Fix:
No patched version reported
Disclosed:
Jun 28, 2021

CVE-2021-24474 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database