← WordPress Vulnerabilities
WordPress security by component

If-So Dynamic Content Personalization

If-So Dynamic Content Personalization displays different WordPress content based on visitor conditions such as location, device, language, or behavior.

If-So Dynamic Content Personalization (if-so) is a WordPress plugin with 10 published CVE records in this archive. The latest tracked vulnerability was published Oct 01, 2026; the highest published CVSS base score is 9.3.

Plugin slug: if-so

CVE-2026-87973: If-So Dynamic Content: Editor stored XSS through conversion names

The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 1.10.2.

PublishedOct 01, 2026
Known safe version1.10.2
Published vulnerabilities for if-so
Safe version
Oct 01, 2026 CVE-2026-87973
If-So Dynamic Content: Editor stored XSS through conversion names
The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 1.10.2.
1.10.2
CVEPending
NVDPending
Oct 01, 2026 CVE-2026-87970
If-So Dynamic Content: Reflected XSS in an unauthenticated AJAX response
The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served as HTML, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who opens a crafted link. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 1.10.2.
1.10.2
CVEPending
NVDPending
Sep 30, 2026 CVE-2026-100507
If-So Dynamic Content Personalization: Cross-site scripting
Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions. The reported impact is browser script execution in the affected site's origin. The injected field, rendering context and exact victim interaction are unspecified. The authoritative export does not identify the vulnerable endpoint, action, parameter or function, so the precise input-to-operation path cannot be established from this snapshot. The authoritative export identifies the fixed release as 1.10.2.
1.10.2
CVE7.1
NVDPending
Aug 13, 2026 CVE-2026-66446
If-So permits Subscriber-level SQL injection
If-So through 1.10 allows a Subscriber to supply data that reaches an unsafe database query, enabling SQL injection. Version 1.10.0.1 is fixed. Its prose explicitly requires a Subscriber even though the published CVSS vector encodes no privileges required; this archive retains the stated role and leaves the vector inconsistency unresolved.
1.10.0.1
CVE9.3
NVDPending
Sep 03, 2025 CVE-2025-58602
If-So Dynamic Content Personalization: Cross-site scripting
If-So Dynamic Content Personalization is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jun 17, 2025 CVE-2025-49875
If-So Dynamic Content Personalization: Cross-site scripting
If-So Dynamic Content Personalization is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jul 13, 2024 CVE-2024-6070
If-So Dynamic Content Personalization: Cross-site scripting
If-So Dynamic Content Personalization is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jul 13, 2024 CVE-2024-5713
If-So Dynamic Content Personalization: Cross-site scripting
If-So Dynamic Content Personalization is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Jun 11, 2024 CVE-2024-34820
If-So Dynamic Content Personalization: A security weakness
If-So Dynamic Content Personalization is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Feb 10, 2024 CVE-2023-51492
If-So Dynamic Content Personalization: Cross-site scripting
If-So Dynamic Content Personalization is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4