VYPR

Flow Payment

by WordPress

CVEs (1)

  • CVE-2026-57857Jul 18, 2026
    risk 0.00cvss epss 0.00

    The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page. When the plugin handles an order cancellation, the error_message GET parameter is passed directly to wc_add_notice() in…