CVE-2026-2466
DukaPress <= 3.2.4 - Reflected XSS
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
11th
The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
| Vendor | unknown |
| Product | dukapress |
| Published | Mar 11, 2026 |
| Last Updated | Apr 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown dukapress
Be the first to know when new high vulnerabilities affecting unknown dukapress are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / DukaPress
0 โค 3.2.4
References
Credits
Vuln Seeker Cyber Security Team WPScan