CVE-2026-1822 | tonysamperi WP NG Weather Plugin up to 1.0.9 on WordPress Shortcode ng-weather cross site scripting
A vulnerability classified as problematic was found in tonysamperi WP NG Weather Plugin up to 1.0.9 on WordPress. Affected by this vulnerability is the function ng-weather of the component Shortcode Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-1822. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.