Back

LOW

If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name

Published Oct 1, 2026

Description

The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved Sep 9, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Received
Modified Oct 1, 2026
Red Hat
Severity n/a
Public date n/a