CVE-2023-0360: Location Weather < 1.3.4 - Contributor+ Stored XSS
The Location Weather WordPress plugin before 1.3.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0360?
CVE-2023-0360 is a vulnerability in the Location Weather WordPress plugin before version 1.3.4 that allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
How severe is CVE-2023-0360?
CVE-2023-0360 has a severity rating of 5.4, which is considered medium.
What software is affected by CVE-2023-0360?
The Location Weather WordPress plugin versions up to and excluding 1.3.4 are affected.
How can I fix CVE-2023-0360?
To fix CVE-2023-0360, update the Location Weather WordPress plugin to version 1.3.4 or later.
What is the CWE ID of CVE-2023-0360?
The CWE ID of CVE-2023-0360 is 79, which is for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').