The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' Block Attribute in all versions up to, and including, 3.1.6. This vulnerability exists due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pag [truncated]
CVE-2026-7249 affects the Location Weather WordPress plugin through 3.0.2. Authenticated users with Contributor-level access or higher can modify plugin state by calling exposed actions that lack capability checks, allowing them to disable weather blocks and purge weather cache transients. The issue is integrity-focused and scored medium severity (CVSS 4.3).