Junglewise Threat Intelligence

CVE-2026-39628: kutethemes DukaMarket XSS and Content Injection

CVE-2026-39628 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Vendors: KuteThemes.

Executive brief

DukaMarket is a WordPress theme used for building e-commerce websites. A security flaw in the theme allows unauthorized individuals to inject malicious scripts or content into the website. This could lead to the display of fraudulent information, phishing pages, or the theft of visitor information, potentially damaging the site's reputation and customer trust.

Technical details

The DukaMarket theme for WordPress (versions up to and including 1.3.0) suffers from a Cross-Site Scripting (XSS) vulnerability due to improper neutralization of script-related HTML tags. This flaw allows an unauthenticated remote attacker to perform code injection or arbitrary shortcode execution. The vulnerability is classified under CWE-80 (Basic XSS) and CWE-79. An attacker can exploit this by sending a specially crafted request to a site running the vulnerable theme, potentially leading to unauthorized content modification or the execution of malicious scripts in the context of a user's browser. As of the advisory date, no official patch has been released.

Affected products

  • kutethemes DukaMarket <= 1.3.0

Timeline

  • 2026-01-13: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-02-12: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD

References