CVE-2024-6070: if-so < 1.8.0.4 - Admin+ Stored XSS
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6070?
CVE-2024-6070 has a medium severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-6070?
To fix CVE-2024-6070, update the If-So Dynamic Content Personalization WordPress plugin to version 1.8.0.4 or later.
Who is affected by CVE-2024-6070?
CVE-2024-6070 affects users of the If-So Dynamic Content Personalization WordPress plugin prior to version 1.8.0.4.
What kind of attacks can be executed due to CVE-2024-6070?
CVE-2024-6070 allows high privilege users to perform Stored Cross-Site Scripting attacks.
What should I do if I cannot update my plugin for CVE-2024-6070?
If unable to update, consider disabling the If-So Dynamic Content Personalization plugin until a fix can be applied.