← WordPress Vulnerabilities
WordPress security by component

Awesome Weather Widget

Awesome Weather Widget is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 14, 2023; the highest CVE/CNA score is 6.4.

Plugin slug: awesome-weather

CVE-2023-4944: Awesome Weather Widget: Cross-site scripting

Awesome Weather Widget is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedSep 14, 2023
Safe version guidanceSee mitigation notes
Safe version
Sep 14, 2023 CVE-2023-4944
Awesome Weather Widget: Cross-site scripting
Awesome Weather Widget is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4