Junglewise Threat Intelligence

CVE-2026-66433: ShapedPlugin LLC Location Weather XSS in Contributor role

CVE-2026-66433 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Executive brief

The Location Weather plugin for WordPress, which allows site owners to display weather information, contains a security vulnerability that could allow users with 'Contributor' level access to inject malicious scripts. If an administrator or another user views the affected content, these scripts could execute, potentially leading to unauthorized actions, website redirects, or the display of malicious advertisements. This could damage a site's reputation and compromise the security of its visitors.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the ShapedPlugin LLC Location Weather plugin for WordPress (versions <= 3.0.6). The flaw is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). It allows an authenticated attacker with 'Contributor' level privileges to inject arbitrary web scripts into the site. Because the input is not properly sanitized, the script is stored and executed in the browser of any user (including administrators) who visits the page where the malicious content is rendered. This requires user interaction (viewing the page) and can lead to session hijacking or unauthorized configuration changes. The issue is resolved in version 3.0.7.

Affected products

  • ShapedPlugin LLC Location Weather <= 3.0.6

Timeline

  • 2026-07-13: other: Reported by researcher to Patchstack
  • 2026-07-27: disclosed: Vulnerability disclosed by Patchstack
  • 2026-07-27: advisory: NVD published CVE-2026-66433
  • 2026-07-27: patched: Patch released in version 3.0.7

References

Related threats