Descrição
The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the -noresults- parameter in all versions up to, and including, 7.8.2 due to insufficient input sanitization and output escaping on the user supplied -noresults- parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVSS 6.1EPSS 0.27%Risco 0.62
Ver fonte- Publicação
- 2026-03-26 04:17:03
- Versões afetadas
- <=7.8.2
- Tipo
- Installed app
- Vetor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N