Cross Site Scripting Vulnerability in SureDash Plugin by SureDash
CVE-2026-66698
7.1HIGH
What is CVE-2026-66698?
An unauthenticated Cross Site Scripting (XSS) vulnerability exists in versions of the SureDash plugin up to 1.10.1. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions and access to sensitive data. Administrators using the affected versions are urged to update to the latest version to mitigate these risks and enhance the security of their web applications.
Affected Version(s)
SureDash <= 1.10.1