← Πίσω στην αναζήτηση CVE

CVE-2026-1986

FloristPress for Woo

Περιγραφή

The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the -noresults- parameter in all versions up to, and including, 7.8.2 due to insufficient input sanitization and output escaping on the user supplied -noresults- parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS 6.1EPSS 0.27%Κίνδυνος 0.62
Προβολή πηγής
Δημοσίευση
2026-03-26 04:17:03
Επηρεαζόμενες εκδόσεις
<=7.8.2
Τύπος
Installed app
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N