← WordPress Vulnerabilities
WordPress security by component

SureDash – Community, Courses & Member Dashboard

SureDash – Community, Courses & Member Dashboard is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 9.9.

Plugin slug: suredash

CVE-2026-15821: SureDash profile shortcode attributes permit stored XSS

SureDash through 1.10.0 lets a Contributor store attacker-controlled menuopenverposition, menuverpositionoffset, menuopenhorposition and menuhorpositionoffset attributes in the [portal_user_profile] shortcode. render_user_profile() concatenates those values into the portal-avatar-menu inline style and outputs the result without attribute escaping, allowing an attribute-breakout payload to execute when a logged-in user views or previews the post.

PublishedJul 24, 2026
Known safe version1.10.1
Safe version
Jul 24, 2026 CVE-2026-15821
SureDash profile shortcode attributes permit stored XSS
SureDash through 1.10.0 lets a Contributor store attacker-controlled menuopenverposition, menuverpositionoffset, menuopenhorposition and menuhorpositionoffset attributes in the [portal_user_profile] shortcode. render_user_profile() concatenates those values into the portal-avatar-menu inline style and outputs the result without attribute escaping, allowing an attribute-breakout payload to execute when a logged-in user views or previews the post.
1.10.1
CVE6.4
NVDPending
Jul 13, 2026 CVE-2026-57401
SureDash: Filesystem traversal
SureDash is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 1.8.0.
1.8.1
CVE9.9
NVDPending
Jun 17, 2026 CVE-2026-54813
SureDash: SQL injection
SureDash is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.8.0.
1.8.1
CVE8.5
NVDPending
Aug 20, 2025 CVE-2025-48164
SureDash: Privilege escalation or authentication bypass
SureDash is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Aug 14, 2025 CVE-2025-54685
SureDash: A security weakness
SureDash is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending