CVE-2025-54685: WordPress SureDash Plugin <= 1.1.0 - Sensitive Data Exposure Vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in Brainstorm Force SureDash allows Retrieve Embedded Sensitive Data. This issue affects SureDash: from n/a through 1.1.0.
Other sources
Insertion of Sensitive Information Into Sent Data vulnerability in Brainstorm Force SureDash suredash allows Retrieve Embedded Sensitive Data.This issue affects SureDash: from n/a through <= 1.1.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54685?
CVE-2025-54685 is considered a medium severity vulnerability due to the potential exposure of sensitive data.
How do I fix CVE-2025-54685?
To fix CVE-2025-54685, update Brainstorm Force SureDash to the latest version beyond 1.1.0.
What versions of SureDash are affected by CVE-2025-54685?
CVE-2025-54685 affects all versions of Brainstorm Force SureDash up to and including 1.1.0.
What types of sensitive data are exposed in CVE-2025-54685?
CVE-2025-54685 can lead to the retrieval of embedded sensitive data that should not be accessible to unauthorized users.
Is the WordPress SureDash Plugin also affected by CVE-2025-54685?
Yes, the WordPress SureDash Plugin is affected by CVE-2025-54685 if using version 1.1.0 or earlier.