Extension WordPress
Vulnérabilités Location Weather – WordPress Weather Forecast, Air Quality & Weather Widget
Cette page rassemble les failles publiées pour Location Weather – WordPress Weather Forecast, Air Quality & Weather Widget, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Location Weather – WordPress Weather Forecast, Air Quality & Weather Widget
2 fiches
Location Weather <= 3.0.2 – Missing Authorization to Authenticated (Contributor+) Block Settings Modification and Cache Purging
The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the `splw_update_block_options()` and `lwp_clean_weather_transients()` functions in all versions up to, and including, 3.0.2. This makes it possible for authenticated…
*-3.0.2
3.0.3
21/05/2026
Location Weather <= 1.3.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes
The Location Weather plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes (such as 'sp_location_weather_pro_shortcode') in versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level…
*-1.3.3
1.3.4
18/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.