CVE-2026-87973: If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name
The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
If-So Dynamic Contentto a version that resolves this vulnerability.Fixed in 1.10.2
Event History
Frequently Asked Questions
Who can exploit this issue, and who is affected when it is triggered?
An attacker needs editor-level access to the WordPress site to save a malicious conversion name. The stored JavaScript executes when a higher-privileged user views the plugin's analytics page.
Which plugin versions are affected?
If-So Dynamic Content versions before 1.10.2 are affected. The reported affected range includes 1.9.9 through 1.10.1.
What is the immediate mitigation if the plugin cannot be updated?
Restrict editor-level access to trusted users and avoid having higher-privileged users view the plugin analytics page until the issue is remediated.