DukaPress - Reflected XSS vulnerability
highReflected XSS vulnerability
- CVSS:
- 7.1
- Affected:
- up to 3.2.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 12, 2026
plugin
4 known security issues reported for the Dukapress WordPress plugin. Most recent disclosed Mar 12, 2026.
Running Dukapress on your site? Check whether your installed version is affected.
Scan your site freeReflected XSS vulnerability
The DukaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...
The DukaPress plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter in the 'dukapress/download.php' file in versions up to, and including, 2.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free