CVE-2026-100507: WordPress If-So Dynamic Content Personalization plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress If-So Dynamic Content – Elementor & All Page Builders Personalization pluginto a version that resolves this vulnerability.Fixed in 1.10.2
Event History
Frequently Asked Questions
Does exploiting this issue require an authenticated WordPress account?
No. The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or existing plugin privileges.
What versions should be treated as affected?
If-So Dynamic Content Personalization versions 1.10.1 and earlier are identified as affected.
What conditions make exploitation easier?
The attack vector is network-based with low attack complexity and requires no privileges, but it does require user interaction. Successful exploitation can affect confidentiality, integrity, and availability at low impact levels.