WordPress Plugin Vulnerabilities

If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name

Description

The plugin does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page.

Proof of Concept

Affects Plugins

Fixed in 1.10.2

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Kaan Özbek
Submitter
Kaan Özbek
Verified
Yes

Timeline

Publicly Published
2026-09-29 (about 2 days ago)
Added
2026-09-29 (about 1 day ago)
Last Updated
2026-09-29 (about 1 day ago)

Other