Description
WordPress Plugin Weather for us-animated weather widget includes JavaScript code that would mine cryptocurrency using the CPU resources of site visitors. This allows the plugin owner to earn money by using the CPU resources of visitors. WordPress Plugin Weather for us-animated weather widget version 1.8 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
SharePoint CVE-2022-41062 Vulnerability (CVE-2022-41062)
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-3057)
WordPress 3.9.x Multiple Vulnerabilities (3.9 - 3.9.19)
WordPress Plugin W3 Total Cache Arbitrary File Disclosure (0.9.3)
WordPress Plugin Automattic Stats Referer Field HTML Injection (1.0)