Impact
The If‑So Dynamic Content WordPress plugin, prior to version 1.10.2, fails to sanitize the conversion name field before storing it and fails to escape the value when rendering the analytics page. An editor‑level user can therefore embed arbitrary JavaScript in a conversion name that is stored, which executes in the browser session of any higher‑privileged user who views that analytics page. This stored cross‑site scripting flaw permits in‑browser code execution with the privileges of the page viewer, potentially enabling session hijacking, defacement, or credential theft.
Affected Systems
WordPress plugin "If‑So Dynamic Content", versions 1.9.9 through 1.10.1.
Risk and Exploitability
The vulnerability is exploitable by users with editor permissions who can create or modify conversion names. Once the malicious JavaScript is stored, it runs when a more privileged user, such as an administrator, views the analytics page, executing the payload in the context of that user’s session. No exploit probability score is available, and the vulnerability is not listed in the CISA KEV catalog. The impact is a potential compromise of higher‑privileged accounts when they visit the affected page; the attack vector is inferred to be the conversion name input exposed to editor users.
OpenCVE Enrichment