HomeDefault status
affected
Any version
affected
Description
The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Problem types
CWE-79 Cross-Site Scripting (XSS)
Product status
Any version
Credits
Vuln Seeker Cyber Security Team
WPScan
References
wpscan.com/...rability/2843e8fe-0c02-48ee-ada3-f1c3d1ee73eb/