Description
WordPress Plugin Weather for us-animated weather widget includes JavaScript code that would mine cryptocurrency using the CPU resources of site visitors. This allows the plugin owner to earn money by using the CPU resources of visitors. WordPress Plugin Weather for us-animated weather widget version 1.8 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
MediaWiki CVE-2017-8812 Vulnerability (CVE-2017-8812)
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-2335)
Apache HTTP Server Other Vulnerability (CVE-2000-0505)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-31549)