Impact
Unauthenticated Cross‑Site Scripting (XSS) exists in the If‑So Dynamic Content Personalization plugin for WordPress versions up to and including 1.10.1. The flaw allows an attacker to inject malicious scripts into web pages that users view, potentially enabling theft of session cookies, hijacking of user accounts, defacement of content, and execution of arbitrary client‑side code. The issue is strictly an input validation problem (CWE‑79) and does not require any special privileges to exploit.
Affected Systems
The vulnerability affects installations of the If‑So Dynamic Content Personalization plugin for WordPress, specifically all versions up to 1.10.1. Site owners using the plugin in conjunction with Elementor or other page builders are directly impacted. No specific operating system or WordPress core version is mentioned, but any WordPress site that has this plugin installed and has not upgraded is susceptible.
Risk and Exploitability
The CVSS score of 7.1 classifies this as high severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated web request to a page served by the vulnerable plugin, meaning any visitor can trigger the XSS. Because no authentication or privileged context is required, the risk to exposed sites is significant, especially for those with managed or shared hosting environments where many users may inadvertently trigger the flaw.
OpenCVE Enrichment