CVE-2026-102774
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-102774, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Image 'alt' Attribute in Community Post Content in all versions up to, and including, 1.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The entity-encoded payload bypasses server-side wp_kses filtering because kses permits the img/alt tag combination and does not normalize entities inside attribute values; the decode occurs client-side when GLightbox reads the .alt DOM property and assigns the result to innerHTML.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
brainstormforce SureDash – Community, Courses & Member Dashboard 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The SureDash WordPress plugin has a stored DOM-based Cross-Site Scripting (XSS) vulnerability in versions up to 1.12.1. It occurs because user-provided image 'alt' text in community posts isn't properly sanitized before being stored or displayed. Attackers with subscriber-level access can inject malicious scripts that execute when other users view the page. The payload bypasses server-side filtering because kses allows img/alt tags and doesn't decode entities in attributes, but the browser decodes them client-side when rendering.

Detection Guidance

To detect this vulnerability, inspect WordPress sites using the SureDash plugin versions up to 1.12.1. Check for malicious scripts in community post content, particularly within img alt attributes. Review server logs for unusual activity from authenticated users with subscriber-level access or higher.

Impact Analysis

If you use this plugin, attackers could steal your cookies, session tokens, or other sensitive data. They might redirect you to malicious sites, deface your WordPress pages, or perform actions on your behalf. Since it requires only subscriber-level access, even low-privilege users could exploit it against higher-privilege users.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. If exploited, it may result in data breaches, triggering mandatory breach notifications and potential fines under these regulations.

Mitigation Strategies

Immediately update the SureDash plugin to the latest version beyond 1.12.1. Remove any suspicious community posts containing img tags with encoded scripts. Implement stricter input validation and output escaping for user-generated content. Monitor affected pages for unexpected script execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102774. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart