PT-2026-28192 · WordPress · Floristpress For Woo – Customize Your Ecommerce Store For Your Florist

·

CVE-2026-1986

·

Published

2026-03-26

·

Updated

2026-03-26

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress versions prior to 7.8.3
Description The software is susceptible to Reflected Cross-Site Scripting due to inadequate input sanitization and output escaping. Specifically, the noresults parameter is not properly handled, allowing unauthenticated attackers to inject arbitrary web scripts. Successful exploitation requires tricking a user into performing an action, such as clicking a malicious link. The affected API endpoint is not specified. The vulnerable parameter is noresults.
Recommendations Update FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress to version 7.8.3 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1986

Affected Products

Floristpress For Woo – Customize Your Ecommerce Store For Your Florist