Impact
The vulnerability originates from inadequate sanitization of the image alt attribute within community post content. An authenticated user with subscriber level or higher can insert an entity‑encoded script that is later decoded by the GLightbox JavaScript when the image alt property is read and assigned to innerHTML. This causes the injected script to execute in the victim’s browser, allowing the attacker to steal session cookies, execute phishing attacks or deliver additional malware.
Affected Systems
All instances of the SureDash – Community, Courses & Member Dashboard WordPress plugin up to and including version 1.12.1 are affected. The flaw is exploitable by any user who has at least subscriber permissions in the WordPress site.
Risk and Exploitability
The CVSS score of 6.4 classifies the issue as moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is authenticated, so an attacker must first obtain a valid WordPress account or compromise an existing one. Once authenticated, the attacker can insert a malicious payload that will execute whenever a victim page containing the injected content is viewed. Despite the lack of known public exploits, the potential to perform session hijacking or phishing makes this a noteworthy risk for sites that rely on this plugin.
OpenCVE Enrichment