Junglewise Threat Intelligence

CVE-2026-54813: Brainstorm Force SureDash blind SQL injection

CVE-2026-54813 · Severity: high · CVSS 8.5 · Published 2026-06-17

Technologies: Brainstorm Force SureDash. Vendors: Brainstorm Force.

Executive brief

SureDash is a WordPress plugin used for creating client dashboards and managing site data. A security vulnerability in this plugin allows an attacker with a basic user account to perform blind SQL injection attacks. This could lead to the unauthorized extraction of sensitive information from the website's database, potentially compromising customer data or site configurations.

Technical details

A blind SQL injection vulnerability exists in the Brainstorm Force SureDash plugin for WordPress due to improper neutralization of special elements in SQL commands (CWE-89). The flaw is present in versions up to and including 1.8.0. An attacker with low-level privileges (such as a Subscriber) can send specially crafted network requests to trigger the vulnerability. Because it is a 'blind' injection, the attacker can infer data from the database based on the application's response patterns or timing. This can result in the theft of sensitive data, though the CVSS vector suggests limited impact on integrity and availability. The issue is resolved in version 1.8.1.

Affected products

  • Brainstorm Force SureDash up to 1.8.0

Timeline

  • 2026-04-27: other: Vulnerability reported by researcher dodoh4t
  • 2026-06-17: advisory: Advisory published by Patchstack and NVD
  • 2026-06-17: patched: Patch released in version 1.8.1

References

Related threats