
CVE-2026-2466 The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting… https://www.cve.org/CVERecord?id=CVE-2026-2466
Post summary
The text announces a Reflected XSS flaw in DukaPress WordPress plugin (v≤3.2.4) and references the CVE record, without providing PoC, exploit, active exploit information, or patch details.
