Flower Delivery by Florist One

Flower Delivery by Florist One has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for Flower Delivery by Florist One has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Flower Delivery by Florist One is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Flower Delivery by Florist One vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2024-11769

Flower Delivery by Florist One <= 3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Flower Delivery by Florist One banner
Latestv3.9.1

Flower Delivery by Florist One

floristone

Author

floristone

3.7(3)
74/100
Last Updated
2024-12-02 (2y ago)
Active Installs
100+
Downloads
8,590
Requires WP
4.1+
Requires PHP
0+
Tested up to
WP 6.5.10
Created
2016-08-18 (10y ago)

Sell fresh flowers on your website with our free plugin and receive a 20% commission on every sale. Florist One handles delivery to the United States and Canada using our network of 15,000 local florists. You make the sale, we take care of order fulfillment, Customer Service and everything else. No integration is needed with any commerce plugin. You don’t even need an SSL certificate though you can use yours if you have one. Install our plugin in minutes and start selling flowers on your website! Data for the plugin is from Florist One: Terms and conditions can be found here in the Affiliate Agreement Our privacy policy can be found here

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C