← Retour à la recherche de CVE

CVE-2026-1986

FloristPress for Woo

Description

The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the -noresults- parameter in all versions up to, and including, 7.8.2 due to insufficient input sanitization and output escaping on the user supplied -noresults- parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS 6.1EPSS 0.27%Risque 0.62
Voir la source
Publication
2026-03-26 04:17:03
Versions concernées
<=7.8.2
Type
Installed app
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N