PatchSiren cyber security CVE debrief
CVE-2026-102774 brainstormforce CVE debrief
The SureDash plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the image 'alt' attribute in community post content. This vulnerability allows authenticated attackers with subscriber-level access to inject web scripts that execute when users access injected pages. The entity-encoded payload bypasses server-side filtering because kses permits the img/alt tag combination and does not normalize entities inside attribute values; the decode occurs client-side when GLightbox reads the .alt DOM property and assigns the result to innerHTML. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up.
- Vendor
- brainstormforce
- Product
- SureDash – Community, Courses & Member Dashboard
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
WordPress site administrators, security teams, and users with subscriber-level access or above on sites using the SureDash plugin should assess exposure and prioritize remediation.
Why it matters
This vulnerability requires attention from WordPress site administrators and security teams due to the potential for authenticated attackers to inject malicious scripts, which can execute on affected pages, impacting site integrity and user trust.
- Potential for authenticated attackers to inject malicious scripts
- Execution of injected scripts when users access affected pages
- Possible impact on site integrity and user trust
- Need for prompt remediation to prevent exploitation
Technical summary
The SureDash plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the image 'alt' attribute in community post content. This is due to insufficient input sanitization and output escaping. Authenticated attackers with subscriber-level access and above can inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The entity-encoded payload bypasses server-side filtering because kses permits the img/alt tag combination and does not normalize entities inside attribute values; the decode occurs client-side when GLightbox reads the .alt DOM property and assigns the result to innerHTML. Review compensating controls for exposed systems while remediation
Defensive priority
Medium-priority defensive actions are required to address this vulnerability, particularly for WordPress site administrators and security teams.
Recommended defensive actions
- Update SureDash to a version beyond 1.12.1 if available
- Implement additional input validation and output encoding for image 'alt' attributes in community post content
- Monitor for suspicious activity related to stored cross-site scripting
- Consider implementing a web application firewall (WAF) to detect and prevent similar attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The vulnerability exists in SureDash versions up to and including 1.12.1. The entity-encoded payload bypasses server-side filtering because kses permits the img/alt tag combination and does not normalize entities inside attribute values; the decode occurs client-side when GLightbox reads the .alt DOM property and assigns the result to innerHTML.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-102774 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-102774
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-102774 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-102774
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
SureDash <= 1.12.1 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Scripting via Image
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/102xxx/CVE-2026-102774.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/suredash/tags/1.12.0/assets/js/minified/lightbox.min.js
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/suredash/tags/1.12.0/core/routers/misc.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/suredash/tags/1.12.0/core/routes.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/suredash/tags/1.12.0/inc/services/router.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/suredash/tags/1.12.0/inc/utils/post-meta.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.