CVE-2021-24474
02.08.2021, 11:15
The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refresh AJAX action, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability.
Vendor | Product | Version |
---|---|---|
awesome_weather_widget_project | awesome_weather_widget | 𝑥 ≤ 3.0.2 |
𝑥
= Vulnerable software versions