Indicator
Type cve · source NVD CVE
Enrichment by provider
Grouped attempts with latest status; expand for attempt history.
3 attempts · first 2026-07-10T14:30:05.814385Z · last 2026-07-21T13:49:57.679393Z
Not listed in CISA KEV (local)
Types: cisa_kev
3 attempts · first 2026-07-10T14:30:05.806534Z · last 2026-07-21T13:49:57.668573Z
EPSS=0.00193
Types: epss
3 attempts · first 2026-07-10T14:30:05.818372Z · last 2026-07-21T13:49:57.682967Z
The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'weather_style' and 'move_direction' parameters of the Weather widget in all versions up to, and including, 2.6.3. This is due to insufficient output escaping in the Weather widget's render() function at widgets/weather.php:1246, where both settings values are placed into an HTML class attr
Types: nvd_local
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
See edges, pivots, and corroboration at a glance.
Full inspector with neighbor expansion.