WordPress security by component
Location Weather
Plugin description
Location Weather displays weather information based on selected locations on WordPress websites.
Location Weather (location-weather) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest published CVSS base score is 6.5.
Plugin slug:
location-weatherLatest vulnerability
CVE-2026-66433: Location Weather contributor input permits cross-site scripting
Location Weather through 3.0.6 lets a Contributor supply attacker-controlled input that reaches a browser-executable output context without adequate neutralization. The payload can execute in the site's origin when another user views the crafted output.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-66433
Location Weather contributor input permits cross-site scripting
Location Weather through 3.0.6 lets a Contributor supply attacker-controlled input that reaches a browser-executable output context without adequate neutralization. The payload can execute in the site's origin when another user views the crafted output.
|
3.0.7 |
CVE6.5
NVDPending
|
| May 22, 2026 |
CVE-2026-7249
Location Weather – WordPress Weather Forecast, AQI, Temperature and Weather Widget: A security weakness
Location Weather – WordPress Weather Forecast, AQI, Temperature and Weather Widget is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.0.2.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 13, 2023 |
CVE-2023-0360
Location Weather: Cross-site scripting
Location Weather is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|