CVE-2021-24474
EUVD-2021-1138602.08.2021, 11:15
The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refresh AJAX action, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| awesome_weather_widget_project | awesome_weather_widget | 𝑥 ≤ 3.0.2 |
𝑥
= Vulnerable software versions