CVE-2026-87973 PUBLISHED

If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name

Assigner: WPScan
Reserved: 09.09.2026 Published: 01.10.2026 Updated: 01.10.2026

The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page.

Product Status

Vendor Unknown
Product If-So Dynamic Content
Versions Default: unaffected
  • affected from 1.9.9 to 1.10.2 (excl.)

Credits

  • Kaan Özbek finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE