WordPress Plugin Vulnerabilities

If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter

Description

The plugin does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.

Proof of Concept

Affects Plugins

Fixed in 1.10.2

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Utkarsh Choudhary
Submitter
Utkarsh Choudhary
Verified
Yes

Timeline

Publicly Published
2026-10-05 (about 2 days ago)
Added
2026-10-05 (about 1 day ago)
Last Updated
2026-10-05 (about 1 day ago)

Other