Description
The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting leading to arbitrary JavaScript execution within the admin browser session
Action: Immediate Patch
AI Analysis

Impact

The If‑So Dynamic Content WordPress plugin versions prior to 1.10.2 fails to validate the URL scheme of a request‑supplied value before reflecting it into a link displayed on an admin page. An attacker can craft a link that includes malicious JavaScript and inject it into the page; when a logged‑in administrator clicks the link, the browser executes the script.

Affected Systems

The vulnerability affects the If‑So Dynamic Content WordPress plugin for all versions 1.4.4 through 1.10.1. Vendors are listed as unknown and the publisher is If‑So Dynamic Content. Any WordPress installation using these plugin releases and running an administrative interface is susceptible.

Risk and Exploitability

Because the flaw requires that a logged‑in administrator view the crafted link, it is an advanced internal attack limited to users with administrative privileges. The EPSS score is currently unavailable and the vulnerability is not recorded in the CISA KEV catalog, but the consequence of arbitrary JavaScript execution in a privileged user context gives it a high potential for damage. The attacker must be able to entice a legitimate user to click the malicious link, yet once executed, the script runs with the full permissions of that user’s session.

Generated by OpenCVE AI on October 7, 2026 at 08:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the If‑So Dynamic Content plugin to version 1.10.2 or later, which implements proper URL scheme validation.
  • If an update cannot be applied immediately, temporarily disable the plugin or revoke administrative access from users until the fix is applied.
  • Restrict the ability to use the vulnerable component to trusted administrators and consider implementing an additional input‑validation layer that blocks non‑http(s) schemes.

Generated by OpenCVE AI on October 7, 2026 at 08:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.
Title If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T06:00:08.472Z

Reserved: 2026-09-09T18:11:57.831Z

Link: CVE-2026-87971

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T07:17:01.950

Modified: 2026-10-07T07:17:01.950

Link: CVE-2026-87971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T08:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')