CVE-2026-57401: WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through <= 1.8.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SureDash pluginto a version that resolves this vulnerability.Fixed in 1.8.0 - Compensating control
Restrict or disable the WordPress SureDash plugin in environments where it is not required until it can be upgraded past the affected range (up to and including 1.8.0).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57401?
CVE-2026-57401 has a critical severity rating of 9.9.
What vulnerability does CVE-2026-57401 describe?
CVE-2026-57401 describes an arbitrary file deletion vulnerability due to improper limitation of a pathname to a restricted directory in the SureDash plugin.
How do I fix CVE-2026-57401?
To fix CVE-2026-57401, update the SureDash plugin to the latest version that resolves the arbitrary file deletion vulnerability.
Which software is affected by CVE-2026-57401?
CVE-2026-57401 affects Brainstorm Force's SureDash plugin, specifically versions from n/a through 1.8.0.
What kind of attacks can CVE-2026-57401 facilitate?
CVE-2026-57401 can facilitate path traversal attacks that may lead to arbitrary file deletion on the affected systems.