Description
The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served as HTML, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who opens a crafted link.
Published: 2026-10-01
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the If‑So Dynamic Content WordPress plugin for versions prior to 1.10.2. A request‑supplied value is not escaped before being reflected in an unauthenticated AJAX response served as HTML, allowing an attacker to inject arbitrary JavaScript into the page viewed by any visitor who follows a crafted link. This reflected cross‑site scripting can lead to the execution of malicious code in the victim’s browser.

Affected Systems

Any WordPress site running the If‑So Dynamic Content plugin version 1.10.1 or older is potentially affected. The issue exists in the AJAX handler that processes the shortcode filter. Sites with the plugin installed and built using default WordPress AJAX endpoints are at risk.

Risk and Exploitability

The vulnerability has no publicly disclosed exploit code and the EPSS score is unavailable. It is not indexed in the CISA KEV catalog. Nonetheless, the flaw permits code execution in the context of an unauthenticated visitor, which can be exploited by directing anyone to a malicious link. Because the attacker does not need authentication and requires only a simple crafted URL, the risk of exploitation is significant on sites that do not mitigate the reflected content. The absence of a public CVSS score does not diminish the potential severity, given that arbitrary JavaScript execution can compromise user accounts and undermine site integrity.

Generated by OpenCVE AI on October 1, 2026 at 08:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the If‑So Dynamic Content plugin to version 1.10.2 or later, which includes proper output escaping.
  • If the site cannot upgrade immediately, disable or deactivate the plugin until the patch is applied.
  • In the interim, restrict access to the affected AJAX endpoint by implementing a firewall rule, .htaccess restriction, or server‑side filter that blocks requests lacking valid authentication or specific query parameters.

Generated by OpenCVE AI on October 1, 2026 at 08:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served as HTML, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who opens a crafted link.
Title If-So Dynamic Content 1.8 - 1.10.1 - Reflected XSS via render_ifso_shortcodes
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-01T10:45:49.471Z

Reserved: 2026-09-09T18:11:21.426Z

Link: CVE-2026-87970

cve-icon Vulnrichment

Updated: 2026-10-01T10:43:50.284Z

cve-icon NVD

Status : Received

Published: 2026-10-01T06:17:12.840

Modified: 2026-10-01T11:17:28.523

Link: CVE-2026-87970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T08:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')