PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66433 ShapedPlugin LLC CVE debrief

A Cross Site Scripting (XSS) vulnerability was found in the Location Weather plugin up to version 3.0.6. This issue allows contributors to inject malicious scripts, potentially leading to unauthorized modifications or data exposure. The vulnerability has a CVSS score of 6.5, indicating a medium severity level. Users of the Location Weather plugin should be aware of this vulnerability and take necessary precautions to mitigate potential risks. The CVE record was published on 2026-07-27T15:17:10.917Z and has not been modified since then.

Vendor
ShapedPlugin LLC
Product
Location Weather
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-07-27
Advisory published
2026-07-27
Advisory updated
2026-07-27

Who should care

Users of Location Weather plugin version 3.0.6 or earlier should be aware of this vulnerability and review their deployments for potential exposure. This includes site administrators, security teams, and developers responsible for maintaining WordPress installations with the Location Weather plugin. Additionally, security teams and vulnerability management professionals should consider this vulnerability when assessing their organization's risk profile and prioritize mitigation efforts accordingly.

Technical summary

The Location Weather plugin for WordPress is vulnerable to Cross Site Scripting (XSS) attacks in versions up to and including 3.0.6. This vulnerability allows authenticated users, specifically contributors, to inject malicious scripts into the plugin. The CVSS score of 6.5 indicates a medium severity level, and the vulnerability can be exploited by contributors with minimal technical expertise. The official CVE record and NVD details provide further information on this vulnerability.

Defensive priority

Medium priority due to the CVSS score of 6.5 and the potential for user exploitation. Organizations should prioritize mitigation efforts based on their risk profile and the potential impact of a successful exploit.

Recommended defensive actions

  • Update Location Weather plugin to a version beyond 3.0.6 if available.
  • Restrict contributor privileges to minimize exploitation risk.
  • Monitor plugin and WordPress core for updates and security advisories.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence from Patchstack indicates a Cross Site Scripting (XSS) vulnerability in Location Weather plugin version 3.0.6. The vulnerability allows contributors to inject malicious scripts. Patchstack's research team verified this issue through limited testing and review of public sources. However, the full scope of affected deployments and potential impact remains uncertain without further information from the vendor or additional sources. Defenders should verify the presence of this vulnerability in their environments and review the official CVE record for guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T15:17:10.917Z and has not been modified since then.