plugin

Dukapress Vulnerabilities

4 known security issues reported for the Dukapress WordPress plugin. Most recent disclosed Mar 12, 2026.

1 critical 3 high

Running Dukapress on your site? Check whether your installed version is affected.

Scan your site free

DukaPress - Reflected XSS vulnerability

high

Reflected XSS vulnerability

CVSS:
7.1
Affected:
up to 3.2.4
Fix:
No patched version reported
Disclosed:
Mar 12, 2026

DukaPress <= 3.2.4 - Unauthenticated Stored Cross-Site Scripting

high

The DukaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...

CVSS:
7.2
Affected:
up to 3.2.4
Fix:
No patched version reported
Disclosed:
Mar 12, 2026

CVE-2026-2466 on NVD →

DukaPress <= 2.5.9 - Blind SQL Injection

critical

The DukaPress plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter in the 'dukapress/download.php' file in versions up to, and including, 2.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...

CVSS:
9.8
Affected:
up to 2.5.9
Fixed in:
2.5.9.1
Disclosed:
Aug 22, 2015

CVE-2015-1000011 on NVD →

DukaPress < 2.5.4 - Directory Traversal

high

Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.

CVSS:
7.5
Affected:
up to 2.5.4
Fixed in:
2.5.4
Disclosed:
Nov 13, 2014

CVE-2014-8799 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database