Reflected Cross-Site Scripting in FloristPress for WooCommerce Plugin
CVE-2026-1986
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 March 2026
What is CVE-2026-1986?
The FloristPress for WooCommerce plugin is susceptible to reflected cross-site scripting, allowing unauthenticated attackers to exploit insufficient input sanitization on the 'noresults' parameter. This security lapse enables attackers to craft malicious scripts that can be injected into web pages. If users interact with links manipulated by these scripts, it may lead to unauthorized actions on the user's session. Websites utilizing versions up to and including 7.8.2 are encouraged to adopt immediate remediation measures.
Affected Version(s)
FloristPress for Woo β Customize your eCommerce store for your Florist 0 <= 7.8.2