CVE-2026-66433
Received Received - Intake

Cross-Site Scripting (XSS) in Location Weather Plugin

Vulnerability report for CVE-2026-66433, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: Patchstack

Description

Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
patchstack location_weather to 3.0.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Contributor Cross Site Scripting (XSS) issue in the WordPress Location Weather plugin versions 3.0.6 and below. It allows attackers to inject malicious scripts into the website through user interactions like clicking links or submitting forms. The injected scripts could redirect visitors or display unwanted content.

Detection Guidance

Check if the Location Weather plugin version is 3.0.6 or below. Use WordPress admin panel to inspect installed plugins or run commands like 'wp plugin list' in WP-CLI to verify versions.

Impact Analysis

If exploited, this vulnerability could allow attackers to execute malicious scripts on your website. Visitors might be redirected to harmful sites or see unwanted advertisements. The impact requires a privileged user to trigger the action, but it could affect all site visitors.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by enabling attackers to inject malicious scripts that steal user data or manipulate website content. XSS vulnerabilities may lead to unauthorized access to sensitive information, violating data protection requirements under these regulations.

Mitigation Strategies

Update the Location Weather plugin to version 3.0.7 or later. Enable auto-update for plugins if using Patchstack to prevent future vulnerabilities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66433. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart