WordPress Plugin Vulnerabilities

If-So Dynamic Content 1.8 - 1.10.1 - Reflected XSS via render_ifso_shortcodes

Description

The plugin does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served as HTML, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who opens a crafted link.

Proof of Concept

Affects Plugins

Fixed in 1.10.2

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
João Ramos Maciel
Submitter
João Ramos Maciel
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-29 (about 2 days ago)
Added
2026-09-29 (about 1 day ago)
Last Updated
2026-09-29 (about 1 day ago)

Other