Junglewise Threat Intelligence

CVE-2026-15821: Brainstorm Force SureDash Stored XSS in Shortcode Attributes

CVE-2026-15821 · Severity: medium · CVSS 6.4 · Published 2026-07-24

Technologies: Brainstorm Force SureDash. Vendors: Brainstorm Force.

Executive brief

The SureDash plugin for WordPress, which provides community and course dashboards, contains a security flaw that allows users with contributor-level access to inject malicious scripts into website pages. These scripts execute automatically when other users, including administrators, visit the affected pages. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.

Technical details

The SureDash plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via shortcode attributes in versions up to and including 1.10.0. The root cause is insufficient input sanitization and output escaping within the plugin's shortcode handling logic, specifically in components like the user profile shortcode. An authenticated attacker with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into a page via a shortcode. These scripts are then stored and executed in the context of any user's browser who visits the compromised page. This vulnerability is tracked as CWE-79 and has been addressed in subsequent updates.

Affected products

  • Brainstorm Force SureDash – Community, Courses & Member Dashboard <= 1.10.0

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References

Related threats