CVE-2024-5440: If-So Dynamic Content Personalization < 1.8.0.3 - Contributor+ Shortcode Stored XSS
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5440?
CVE-2024-5440 has a medium severity rating due to its potential for storing malicious content.
How do I fix CVE-2024-5440?
To fix CVE-2024-5440, update the If-So Dynamic Content Personalization plugin to version 1.8.0.3 or later.
Who is affected by CVE-2024-5440?
CVE-2024-5440 affects users with contributor roles and above who utilize the If-So Dynamic Content Personalization plugin.
What type of vulnerability is CVE-2024-5440?
CVE-2024-5440 is an output escaping vulnerability that affects the shortcode attributes in the If-So Dynamic Content Personalization plugin.
What could happen if CVE-2024-5440 is exploited?
If exploited, CVE-2024-5440 could allow a malicious user to inject harmful scripts into posts or pages.