Stored DOM-Based Cross-Site Scripting in SureDash Community Plugin for WordPress
CVE-2026-102774

6.4MEDIUM

What is CVE-2026-102774?

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is susceptible to stored DOM-based cross-site scripting due to inadequate sanitization of input and output. Authenticated attackers with subscriber-level access can exploit this vulnerability by injecting harmful scripts through the 'alt' attribute of image tags in community post content. The flaw arises because certain filters do not normalize entities properly within attribute values, allowing attacker-controlled scripts to execute when a page is accessed. This poses significant security risks for users interacting with compromised content.

Affected Version(s)

SureDash – Community, Courses & Member Dashboard 0 <= 1.12.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dzaku
.