CVE-2026-18402 | brainstormforce SureDash Plugin up to 1.10.3 on WordPress Shortcode esc_attr draweropenverposition cross site scripting

SecurityVulns

A vulnerability described as problematic has been identified in brainstormforce SureDash Plugin up to 1.10.3 on WordPress. This affects the function esc_attr of the component Shortcode Handler. Executing a manipulation of the argument draweropenverposition can lead to cross site scripting.

This vulnerability is tracked as CVE-2026-18402. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More