Weather Effect – Christmas, Santa, Snow Falling, Snowflake Effect [weather-effect] < 1.3.4
unknown
[en] The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Oct 11, 2021
CVE-2021-24683 on NVD →
Weather Effect – Christmas, Santa, Snow Falling, Snowflake Effect [weather-effect] < 1.3.6
unknown
[en] The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting issues
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Oct 11, 2021
CVE-2021-24709 on NVD →
Weather Effect – Christmas Santa Snow Falling <= 1.3.3 - Cross-Site Request Forgery
high
The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.
- CVSS:
- 8.8
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Sep 7, 2021
CVE-2021-24683 on NVD →
Weather Effect – Christmas Santa Snow Falling <= 1.3.5 - Stored Cross-Site Scripting
medium
The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting issues
- CVSS:
- 4.8
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.6
- Disclosed:
- Sep 7, 2021
CVE-2021-24709 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database