CVE-2026-15299 | wealcoder Animation Addons for Elementor Plugin up to 2.6.3 Weather Widget widgets/weather.php render weather_style/move_direction cross site scripting
A vulnerability classified as problematic has been found in wealcoder Animation Addons for Elementor Plugin up to 2.6.3. This impacts the function render of the file widgets/weather.php of the component Weather Widget. Performing a manipulation of the argument weather_style/move_direction results in cross site scripting.
This vulnerability is reported as CVE-2026-15299. The attack is possible to be carried out remotely. No exploit exists.