Description
The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page.
Published: 2026-10-01
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The If‑So Dynamic Content WordPress plugin, prior to version 1.10.2, fails to sanitize the conversion name field before storing it and fails to escape the value when rendering the analytics page. An editor‑level user can therefore embed arbitrary JavaScript in a conversion name that is stored, which executes in the browser session of any higher‑privileged user who views that analytics page. This stored cross‑site scripting flaw permits in‑browser code execution with the privileges of the page viewer, potentially enabling session hijacking, defacement, or credential theft.

Affected Systems

WordPress plugin "If‑So Dynamic Content", versions 1.9.9 through 1.10.1.

Risk and Exploitability

The vulnerability is exploitable by users with editor permissions who can create or modify conversion names. Once the malicious JavaScript is stored, it runs when a more privileged user, such as an administrator, views the analytics page, executing the payload in the context of that user’s session. No exploit probability score is available, and the vulnerability is not listed in the CISA KEV catalog. The impact is a potential compromise of higher‑privileged accounts when they visit the affected page; the attack vector is inferred to be the conversion name input exposed to editor users.

Generated by OpenCVE AI on October 1, 2026 at 07:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the If‑So Dynamic Content plugin to version 1.10.2 or later.
  • If an upgrade is not immediately feasible, remove or disable the plugin, or revoke editor rights for users who can create or edit conversion names.
  • Consider implementing a Content Security Policy to restrict the execution of untrusted scripts on the analytics page.

Generated by OpenCVE AI on October 1, 2026 at 07:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page.
Title If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-01T10:45:49.337Z

Reserved: 2026-09-09T18:12:56.431Z

Link: CVE-2026-87973

cve-icon Vulnrichment

Updated: 2026-10-01T10:43:40.879Z

cve-icon NVD

Status : Received

Published: 2026-10-01T06:17:13.267

Modified: 2026-10-01T11:17:28.690

Link: CVE-2026-87973

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T07:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')