Reflected Cross-Site Scripting in FloristPress for WooCommerce Plugin
CVE-2026-1986

6.1MEDIUM

What is CVE-2026-1986?

The FloristPress for WooCommerce plugin is susceptible to reflected cross-site scripting, allowing unauthenticated attackers to exploit insufficient input sanitization on the 'noresults' parameter. This security lapse enables attackers to craft malicious scripts that can be injected into web pages. If users interact with links manipulated by these scripts, it may lead to unauthorized actions on the user's session. Websites utilizing versions up to and including 7.8.2 are encouraged to adopt immediate remediation measures.

Affected Version(s)

FloristPress for Woo – Customize your eCommerce store for your Florist 0 <= 7.8.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
.