A Cross Site Scripting (XSS) vulnerability was found in the Location Weather plugin up to version 3.0.6. This issue allows contributors to inject malicious scripts, potentially leading to unauthorized modifications or data exposure. The vulnerability has a CVSS score of 6.5, indicating a medium severity level. Users of the Location Weather plugin should be aware of this vulnerability and take necessary pr [truncated]
A Deserialization of Untrusted Data vulnerability was discovered in ShapedPlugin LLC Real Testimonials testimonial-free, potentially allowing Object Injection. The issue affects Real Testimonials versions from n/a through <= 3.1.15. The CVSS score for this vulnerability is 7.2, indicating a HIGH severity. This vulnerability could allow attackers to inject objects, potentially leading to security breaches. [truncated]
CVE-2026-49777 is a critical vulnerability in the Product Slider Pro for WooCommerce plugin, caused by improper validation of specified quantity in input. This vulnerability, with a CVSS score of 10, allows for malicious software to be implanted. The affected versions of the plugin are from n/a to 3.5.4.