Executive brief
SureDash, a WordPress plugin used for client dashboards and portal management, contains a critical security flaw. An attacker with basic user permissions can exploit this vulnerability to delete important files from the web server. This could lead to a complete website failure, loss of data, or the removal of security configurations, effectively taking the business's online presence offline.
Technical details
A path traversal vulnerability (CWE-22) exists in the Brainstorm Force SureDash plugin for WordPress due to improper limitation of pathnames to a restricted directory. An authenticated attacker with low-level privileges can provide manipulated file paths to trigger arbitrary file deletion on the server. This can be used to delete critical system or application files, potentially leading to a denial-of-service (DoS) or bypassing security controls by removing configuration files. The vulnerability is resolved in version 1.8.1.
Affected products
- Brainstorm Force SureDash <= 1.8.0
Timeline
- 2026-04-28: disclosed: Reported by hhhai via Patchstack
- 2026-07-08: advisory: Patchstack published advisory
- 2026-07-13: advisory: NVD published CVE record
- patched: Fixed in version 1.8.1