📦

weather_effect

Vendor: awplife

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 0.16% Exploit Prob.
Latest CVE CVE-2021-24709 Oct 11

Security Vulnerability Index

Page 1 / 1
4.8 CVSS

The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting issues

EPSS: 0.21%
5.4 CVSS

The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.

EPSS: 0.11%