
CVE-2026-7249 The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the `splw_update_block_options()` and `… https://www.cve.org/CVERecord?id=CVE-2026-7249
Post summary
The post reports that the Location Weather WordPress plugin is vulnerable to unauthorized data modification due to missing capability checks on splw_update_block_options, and links to the CVE-2026-7249 record.
