Sceawere

Vulnerability Detail

CVE-2026-102774UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored DOM XSS in SureDash

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
2h ago
Vendor
brainstormforce
Product
SureDash – Community, Courses & Member Dashboard
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Image 'alt' Attribute in Community Post Content in all versions up to, and including, 1.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The entity-encoded payload bypasses server-side wp_kses filtering because kses permits the img/alt tag combination and does not normalize entities inside attribute values; the decode occurs client-side when GLightbox reads the .alt DOM property and assigns the result to innerHTML.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T08:17:03.650Z",
  "pubdate": "2026-10-10T08:17:03.650Z",
  "executiveSummary": "The SureDash – Community, Courses & Member Dashboard plugin for WordPress is affected by a Stored DOM-Based Cross-Site Scripting (XSS) vulnerability in all versions up to, and including, 1.12.1.\nThis vulnerability originates from insufficient input sanitization and output escaping within the image 'alt' attribute handling of community post content.\nThe flaw permits authenticated users with subscriber-level privileges or higher to inject malicious web scripts. These scripts are executed within the browser of any user who views the affected post.\nThe risk is significant as it allows for the execution of arbitrary JavaScript, potentially leading to unauthorized actions, session hijacking, or the defacement of the platform.\nThe exploitation is facilitated by a failure to account for client-side entity decoding performed by the GLightbox library, which renders server-side sanitization measures like wp_kses ineffective in this context.\nAttackers can leverage this vulnerability to gain unauthorized access to sensitive information or perform actions on behalf of legitimate users, including administrators, by compromising their sessions.",
  "technicalDetails": "The vulnerability resides in the way the SureDash plugin handles image 'alt' attributes within community post content. The root cause is a failure to properly sanitize input before storage and a subsequent reliance on unsafe client-side processing.\nThe WordPress security filter 'wp_kses' is intended to strip malicious code from user-supplied HTML. However, 'wp_kses' permits the 'img' tag and its 'alt' attribute. Because the filter does not normalize HTML entities embedded within these attribute values, an attacker can supply an entity-encoded payload that bypasses server-side validation.\nThe exploitation flow begins when an authenticated subscriber-level user creates or updates a community post containing an <img> tag with a malicious 'alt' attribute, such as '<img alt=\"&#60;img src=x onerror=alert(1)&#62;\">'. The server accepts this input because the payload is entity-encoded, appearing benign to 'wp_kses'.\nOnce the post is stored in the database and rendered on a page, the client-side GLightbox library processes the post content. GLightbox specifically reads the 'alt' property of the image element and programmatically assigns that string value to an element's 'innerHTML' property.\nAt this stage, the browser decodes the HTML entities contained in the 'alt' attribute, converting them back into functional HTML tags. The assignment to 'innerHTML' causes the browser to interpret and execute the injected script, triggering the XSS payload in the context of the victim's active session.\nThis represents a classic DOM-based XSS vulnerability where the server serves legitimate-looking data, but the client-side processing logic introduces a security flaw. Because the script executes in the victim's browser, it inherits the victim's session cookies and permissions, enabling the attacker to perform actions as the victim, access protected information, or perform further client-side attacks.\nThe issue affects all plugin versions up to and including 1.12.1. The attack is accessible to any user with the ability to create community posts, effectively meaning any subscriber-level authenticated account is capable of executing this attack across the platform."
}
CVE-2026-102774: Stored DOM XSS in SureDash (MEDIUM Severity, CVSS: 6.4) | Sceawere