Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through <= 1.8.0.
Published: 2026-07-13
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Path Traversal flaw (CWE-22) that allows an attacker to supply a crafted file path and delete arbitrary files on the web server. By bypassing the plugin's directory restrictions, the attacker can remove critical application files, configuration files, or data, leading to loss of data, service disruption, and potentially enabling further exploitation if key plugins or scripts are removed.

Affected Systems

The affected product is Brainstorm Force's SureDash WordPress plugin. All releases from the initial version through 1.8.0 are vulnerable. Site administrators running any of these versions, enabled, are at risk.

Risk and Exploitability

The CVSS score of 9.9 indicates full confidentiality, integrity, and availability impact can be achieved by a remote attacker with network access to the WordPress site. The EPSS score of < 1% suggests a low current probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote endpoint. An attacker would need to craft a specially constructed request, typically through the WordPress admin interface or any exposed file manipulation API, to trigger the deletion outside the intended directory.

Generated by OpenCVE AI on July 31, 2026 at 11:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SureDash to a version newer than 1.8.0 that includes the path traversal fix.
  • If an upgrade is not immediately possible, disable the plugin or lock its file deletion feature so that only trusted administrators can access it.
  • Continuously monitor site logs and perform file integrity checks to detect unexpected deletions or unauthorized file changes.

Generated by OpenCVE AI on July 31, 2026 at 11:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Brainstorm Force
Brainstorm Force suredash
Wordpress
Wordpress wordpress
Vendors & Products Brainstorm Force
Brainstorm Force suredash
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through <= 1.8.0.
Title WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Brainstorm Force Suredash
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:47:52.263Z

Reserved: 2026-06-24T12:46:07.752Z

Link: CVE-2026-57401

cve-icon Vulnrichment

Updated: 2026-07-13T13:47:48.890Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')