PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-102774 brainstormforce CVE debrief

The SureDash plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the image 'alt' attribute in community post content. This vulnerability allows authenticated attackers with subscriber-level access to inject web scripts that execute when users access injected pages. The entity-encoded payload bypasses server-side filtering because kses permits the img/alt tag combination and does not normalize entities inside attribute values; the decode occurs client-side when GLightbox reads the .alt DOM property and assigns the result to innerHTML. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up.

Vendor
brainstormforce
Product
SureDash – Community, Courses & Member Dashboard
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

WordPress site administrators, security teams, and users with subscriber-level access or above on sites using the SureDash plugin should assess exposure and prioritize remediation.

Why it matters

This vulnerability requires attention from WordPress site administrators and security teams due to the potential for authenticated attackers to inject malicious scripts, which can execute on affected pages, impacting site integrity and user trust.

  • Potential for authenticated attackers to inject malicious scripts
  • Execution of injected scripts when users access affected pages
  • Possible impact on site integrity and user trust
  • Need for prompt remediation to prevent exploitation

Technical summary

The SureDash plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the image 'alt' attribute in community post content. This is due to insufficient input sanitization and output escaping. Authenticated attackers with subscriber-level access and above can inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The entity-encoded payload bypasses server-side filtering because kses permits the img/alt tag combination and does not normalize entities inside attribute values; the decode occurs client-side when GLightbox reads the .alt DOM property and assigns the result to innerHTML. Review compensating controls for exposed systems while remediation

Defensive priority

Medium-priority defensive actions are required to address this vulnerability, particularly for WordPress site administrators and security teams.

Recommended defensive actions

  • Update SureDash to a version beyond 1.12.1 if available
  • Implement additional input validation and output encoding for image 'alt' attributes in community post content
  • Monitor for suspicious activity related to stored cross-site scripting
  • Consider implementing a web application firewall (WAF) to detect and prevent similar attacks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The vulnerability exists in SureDash versions up to and including 1.12.1. The entity-encoded payload bypasses server-side filtering because kses permits the img/alt tag combination and does not normalize entities inside attribute values; the decode occurs client-side when GLightbox reads the .alt DOM property and assigns the result to innerHTML.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-102774 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-102774

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-102774 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-102774

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • SureDash <= 1.12.1 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Scripting via Image

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/102xxx/CVE-2026-102774.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/suredash/tags/1.12.0/assets/js/minified/lightbox.min.js

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/suredash/tags/1.12.0/core/routers/misc.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/suredash/tags/1.12.0/core/routes.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/suredash/tags/1.12.0/inc/services/router.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/suredash/tags/1.12.0/inc/utils/post-meta.php

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.