Description
Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
Published: 2026-09-30
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Immediate Patch
AI Analysis

Impact

Unauthenticated Cross‑Site Scripting (XSS) exists in the If‑So Dynamic Content Personalization plugin for WordPress versions up to and including 1.10.1. The flaw allows an attacker to inject malicious scripts into web pages that users view, potentially enabling theft of session cookies, hijacking of user accounts, defacement of content, and execution of arbitrary client‑side code. The issue is strictly an input validation problem (CWE‑79) and does not require any special privileges to exploit.

Affected Systems

The vulnerability affects installations of the If‑So Dynamic Content Personalization plugin for WordPress, specifically all versions up to 1.10.1. Site owners using the plugin in conjunction with Elementor or other page builders are directly impacted. No specific operating system or WordPress core version is mentioned, but any WordPress site that has this plugin installed and has not upgraded is susceptible.

Risk and Exploitability

The CVSS score of 7.1 classifies this as high severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated web request to a page served by the vulnerable plugin, meaning any visitor can trigger the XSS. Because no authentication or privileged context is required, the risk to exposed sites is significant, especially for those with managed or shared hosting environments where many users may inadvertently trigger the flaw.

Generated by OpenCVE AI on September 30, 2026 at 14:58 UTC.

Remediation

Vendor Solution

Update the WordPress If-So Dynamic Content – Elementor & All Page Builders Personalization plugin to the latest available version (at least 1.10.2).


OpenCVE Recommended Actions

  • Update the If‑So Dynamic Content Personalization plugin to version 1.10.2 or newer.
  • If the plugin remains required, disable or limit the feature that allows arbitrary JavaScript injection through the plugin’s settings or by removing custom user scripts.
  • Implement a site‑wide Content Security Policy that blocks inline scripts and restricts script sources to trusted domains to mitigate any residual XSS payloads.

Generated by OpenCVE AI on September 30, 2026 at 14:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
Title WordPress If-So Dynamic Content Personalization plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:37:19.524Z

Reserved: 2026-09-26T00:17:50.215Z

Link: CVE-2026-100507

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:14.577

Modified: 2026-09-30T14:17:21.957

Link: CVE-2026-100507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T15:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')