CVE-2026-87971: If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter
The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites using If-So Dynamic Content versions 1.4.4 through 1.10.1 are affected. Exploitation targets a logged-in user who can be induced to open an attacker-crafted link that reaches the affected admin page.
Does an attacker need an account or special access?
No attacker authentication is required, but the attacker must persuade a logged-in user to visit the crafted URL. User interaction is required for the malicious JavaScript to execute.
What should be done to remediate the issue?
Update If-So Dynamic Content to version 1.10.2 or later. The vulnerable behavior affects versions before 1.10.2.