What is CVE-2026-18402?
Stored Cross-Site Scripting vulnerability discovered in the SureDash WordPress plugin up to version 1.10.3 through the 'draweropenverposition' attribute. Insufficient input sanitization and output escaping allow authenticated users to inject malicious scripts. Immediate plugin update is required.
Azərbaycanca: SureDash WordPress plaginində (1.10.3-ə qədər bütün versiyalar) 'draweropenverposition' atributu vasitəsilə saxlanılan XSS zəifliyi aşkarlanıb. Bu, girişin yetərsiz təmizlənməsi və çıxışın qorunmaması səbəbindən autentifikasiya olunmuş istifadəçilərə zərərli skript yerləşdirməyə imkan verir. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Through which attribute is the CVE-2026-18402 vulnerability in the SureDash plugin exploited?
The vulnerability is exploited through the 'draweropenverposition' attribute.
What action should be taken to address the CVE-2026-18402 vulnerability?
The SureDash plugin should be updated to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.