Impact
This vulnerability permits an authenticated contributor or higher to inject arbitrary JavaScript code into the Shortcode attributes of the SureDash plugin. Because the input is not sanitized and the output is not escaped, the injected code is stored and executed whenever any user views a page that contains the shortcode. An attacker could hijack sessions, steal credentials, deface the site, or launch further attacks on visitors, exemplifying a classic stored XSS (CWE‑79).
Affected Systems
All WordPress sites that have installed the SureDash – Community, Courses & Member Dashboard plugin version 1.10.0 or earlier. The affected product is the SureDash plugin for WordPress, supplied by brainstormforce. Sites that have not upgraded beyond 1.10.0 remain vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate risk level. The EPSS score is reported as less than 1 %, showing a low but existent likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need an account with at least contributor privileges, a common level of access on many sites. Once authenticated, the attacker can add or edit content containing the vulnerable shortcode. The stored payload persists until the site is patched or the shortcode removed, exposing site visitors to potential malicious scripts. Overall, the risk to site owners is moderate, while the potential impact on users could be significant.
OpenCVE Enrichment