Snow Storm
Snow Storm has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.1 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Snow Storm has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Skalucy. Snow Storm is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-30858Snow Storm <= 1.4.6 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

Snow Storm
Author
Tribulant Software
Display falling snow flakes on the front of your WordPress website for a festive presentation. Useful Links: Online Documentation Live Demonstration of Snow Storm plugin Get Support for Snow Storm plugin The Snow Storm plugin was developed by Tribulant Software so that WordPress website owners can display falling snow during the festive season eg. Christmas to decorate their website.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C