Flowbox
Flowbox has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Flowbox has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Muhammad Nur Ibnu Hubab. Flowbox is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2025-49338Flowbox <= 1.1.5 - Missing Authorization
Read the full analysisVulnerability Records

Flowbox
Author
Flowbox
Flowbox Flowbox is an award-winning SaaS company offering a User Generated Content platform developed for established eCommerce brands. Flowbox helps brands leverage and distribute social content throughout the buyer journey to increase engagement, social proof and sales. Through our platform, our customers are able to collect, moderate and publish content to their website, online shop and social channels. Flowbox was founded in 2016 and is headquartered in Stockholm with regional offices in Amsterdam and Barcelona. Get started You must have an active Flowbox account to use Flowbox on your website. You must have WooCommerce installed and activated on your WordPress website to use the Flowbox plugin. Get started with our guide here: Installing the Flowbox plugin for WordPress with WooCommerce
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C