WordPress security by component
SureDash – Community, Courses & Member Dashboard
Plugin description
SureDash – Community, Courses & Member Dashboard is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 9.9.
Plugin slug:
suredashLatest vulnerability
CVE-2026-15821: SureDash profile shortcode attributes permit stored XSS
SureDash through 1.10.0 lets a Contributor store attacker-controlled menuopenverposition, menuverpositionoffset, menuopenhorposition and menuhorpositionoffset attributes in the [portal_user_profile] shortcode. render_user_profile() concatenates those values into the portal-avatar-menu inline style and outputs the result without attribute escaping, allowing an attribute-breakout payload to execute when a logged-in user views or previews the post.
| Safe version |
|
||
|---|---|---|---|
| Jul 24, 2026 |
CVE-2026-15821
SureDash profile shortcode attributes permit stored XSS
SureDash through 1.10.0 lets a Contributor store attacker-controlled menuopenverposition, menuverpositionoffset, menuopenhorposition and menuhorpositionoffset attributes in the [portal_user_profile] shortcode. render_user_profile() concatenates those values into the portal-avatar-menu inline style and outputs the result without attribute escaping, allowing an attribute-breakout payload to execute when a logged-in user views or previews the post.
|
1.10.1 |
CVE6.4
NVDPending
|
| Jul 13, 2026 |
CVE-2026-57401
SureDash: Filesystem traversal
SureDash is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 1.8.0.
|
1.8.1 |
CVE9.9
NVDPending
|
| Jun 17, 2026 |
CVE-2026-54813
SureDash: SQL injection
SureDash is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.8.0.
|
1.8.1 |
CVE8.5
NVDPending
|
| Aug 20, 2025 |
CVE-2025-48164
SureDash: Privilege escalation or authentication bypass
SureDash is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Aug 14, 2025 |
CVE-2025-54685
SureDash: A security weakness
SureDash is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|