Description
WordPress Plugin Weather for us-animated weather widget includes JavaScript code that would mine cryptocurrency using the CPU resources of site visitors. This allows the plugin owner to earn money by using the CPU resources of visitors. WordPress Plugin Weather for us-animated weather widget version 1.8 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
Roundcube Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-19205)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-29450)
WordPress Ultimate Member Plugin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10673)
Oracle HTTP Server CVE-2013-1862 Vulnerability (CVE-2013-1862)