Impact
The If‑So Dynamic Content WordPress plugin versions prior to 1.10.2 fails to validate the URL scheme of a request‑supplied value before reflecting it into a link displayed on an admin page. An attacker can craft a link that includes malicious JavaScript and inject it into the page; when a logged‑in administrator clicks the link, the browser executes the script.
Affected Systems
The vulnerability affects the If‑So Dynamic Content WordPress plugin for all versions 1.4.4 through 1.10.1. Vendors are listed as unknown and the publisher is If‑So Dynamic Content. Any WordPress installation using these plugin releases and running an administrative interface is susceptible.
Risk and Exploitability
Because the flaw requires that a logged‑in administrator view the crafted link, it is an advanced internal attack limited to users with administrative privileges. The EPSS score is currently unavailable and the vulnerability is not recorded in the CISA KEV catalog, but the consequence of arbitrary JavaScript execution in a privileged user context gives it a high potential for damage. The attacker must be able to entice a legitimate user to click the malicious link, yet once executed, the script runs with the full permissions of that user’s session.
OpenCVE Enrichment