Impact
The vulnerability resides in the If‑So Dynamic Content WordPress plugin for versions prior to 1.10.2. A request‑supplied value is not escaped before being reflected in an unauthenticated AJAX response served as HTML, allowing an attacker to inject arbitrary JavaScript into the page viewed by any visitor who follows a crafted link. This reflected cross‑site scripting can lead to the execution of malicious code in the victim’s browser.
Affected Systems
Any WordPress site running the If‑So Dynamic Content plugin version 1.10.1 or older is potentially affected. The issue exists in the AJAX handler that processes the shortcode filter. Sites with the plugin installed and built using default WordPress AJAX endpoints are at risk.
Risk and Exploitability
The vulnerability has no publicly disclosed exploit code and the EPSS score is unavailable. It is not indexed in the CISA KEV catalog. Nonetheless, the flaw permits code execution in the context of an unauthenticated visitor, which can be exploited by directing anyone to a malicious link. Because the attacker does not need authentication and requires only a simple crafted URL, the risk of exploitation is significant on sites that do not mitigate the reflected content. The absence of a public CVSS score does not diminish the potential severity, given that arbitrary JavaScript execution can compromise user accounts and undermine site integrity.
OpenCVE Enrichment