Impact
Unauthenticated cross-site scripting is present in the SureDash WordPress plugin versions 1.10.1 and earlier. This flaw, identified as CWE‑79, allows an attacker to inject malicious scripts into pages rendered by the plugin.
Affected Systems
WordPress installations that have the SureDash plugin from Brainstorm Force installed at version 1.10.1 or older are affected. Any site running those versions is vulnerable unless the plugin is upgraded.
Risk and Exploitability
The CVSS score is 7.1, indicating moderate to high severity. EPSS is not available and KEV not listed, so no current exploitation data is known. No authentication is required to trigger the vulnerability.
OpenCVE Enrichment