Impact
The vulnerability is a stored XSS in the If-So Dynamic Content Personalization plugin. Improper neutralization of user-supplied data enables an attacker to execute arbitrary scripts in visitors’ browsers, potentially stealing session cookies, defacing content, or redirecting users, which compromises confidentiality and authenticity of user accounts. This is a classic input validation flaw (CWE-79).
Affected Systems
The plugin is affected from any version up to and including 1.9.4. It is used by WordPress sites that have installed the If‑So Dynamic Content Personalization add‑on. No vendor name beyond If‑So Dynamic Content is listed, but the impact applies to all sites using the plugin prior to 1.9.5.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate‑to‑high severity. The EPSS score is less than 1%, implying low current exploitation probability, and it is not in the CISA KEV catalog. The likely attack vector is through the plugin’s interface or when a site visitor loads a page that the plugin has processed; a crafted query or content element can inject malicious script that later runs in users’ browsers. Because stored XSS persists while the vulnerable code remains deployed, the risk remains present as long as the plugin is not upgraded.
OpenCVE Enrichment
EUVD