VYPR

Owm Weather

by Ujsoftware

CVEs (2)

  • CVE-2022-3769HigNov 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The OWM Weather WordPress plugin before 5.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as contributor

  • CVE-2022-47179MedFeb 28, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Uwe Jacobs OWM Weather plugin <= 5.6.11 leads to post duplication as a draft.