plugin

Bakkbone Florist Companion Vulnerabilities

8 known security issues reported for the Bakkbone Florist Companion WordPress plugin. Most recent disclosed Mar 30, 2026.

1 high 4 medium

Running Bakkbone Florist Companion on your site? Check whether your installed version is affected.

Scan your site free

FloristPress - Reflected Cross-Site Scripting via 'noresults' Parameter vulnerability

high

Reflected Cross-Site Scripting via 'noresults' Parameter vulnerability

CVSS:
7.1
Affected:
up to 7.8.2
Fixed in:
7.8.3
Disclosed:
Mar 30, 2026

FloristPress for Woo <= 7.8.2 - Reflected Cross-Site Scripting via 'noresults' Parameter

medium

The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'noresults' parameter in all versions up to, and including, 7.8.2 due to insufficient input sanitization and output escaping on the user supplied 'noresults' parameter....

CVSS:
6.1
Affected:
up to 7.8.2
Fixed in:
7.8.3
Disclosed:
Mar 25, 2026

CVE-2026-1986 on NVD →

FloristPress – Customize your Woo store for your Florist [bakkbone-florist-companion] < 7.3.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BAKKBONE Australia FloristPress allows Reflected XSS.This issue affects FloristPress: from n/a through 7.2.0.

Affected:
up to 7.3.0
Fixed in:
7.3.0
Disclosed:
Dec 13, 2024

CVE-2024-54347 on NVD →

FloristPress <= 7.2.0 - Reflected Cross-Site Scripting

medium

The FloristPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...

CVSS:
6.1
Affected:
up to 7.2.0
Fixed in:
7.3.0
Disclosed:
Dec 11, 2024

CVE-2024-54347 on NVD →

FloristPress – Customize your Woo store for your Florist [bakkbone-florist-companion] < 7.4.0

unknown

[en] Missing Authorization vulnerability in BAKKBONE Australia FloristPress.This issue affects FloristPress: from n/a through 7.3.0.

Affected:
up to 7.4.0
Fixed in:
7.4.0
Disclosed:
Dec 9, 2024

CVE-2024-53798 on NVD →

FloristPress – Customize your Woo store for your Florist [bakkbone-florist-companion] < 7.4.0

unknown

[en] Missing Authorization vulnerability in BAKKBONE Australia FloristPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FloristPress: from n/a through 7.3.0.

Affected:
up to 7.4.0
Fixed in:
7.4.0
Disclosed:
Dec 6, 2024

CVE-2024-53799 on NVD →

FloristPress <= 7.3.0 - Missing Authorization to Arbitrary Content Deletion

medium

The FloristPress – Customize your Woo store for your Florist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in all versions up to, and including, 7.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitr...

CVSS:
5.4
Affected:
up to 7.3.0
Fixed in:
7.4.0
Disclosed:
Dec 2, 2024

CVE-2024-53798 on NVD →

FloristPress <= 7.3.0 - Missing Authorization to Sensitive Data Exposure

medium

The FloristPress – Customize your Woo store for your Florist plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in all versions up to, and including, 7.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to access sensitive in...

CVSS:
4.3
Affected:
up to 7.3.0
Fixed in:
7.4.0
Disclosed:
Dec 2, 2024

CVE-2024-53799 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database