Sceawere
Vulnerability Detail
CVE-2026-100507UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in If-So
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- If-So Dynamic Content
- Product
- If-So Dynamic Content Personalization
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:14.577Z",
"pubdate": "2026-09-30T13:17:14.577Z",
"executiveSummary": "The If-So Dynamic Content Personalization plugin for WordPress, in versions 1.10.1 and below, contains a critical security vulnerability involving unauthenticated Cross-Site Scripting (XSS).\nThis vulnerability allows remote, unauthenticated attackers to inject malicious JavaScript into the rendered web pages of a target site.\nThe flaw stems from insufficient input sanitization of user-supplied data, which is subsequently reflected back to users without proper encoding.\nSuccessful exploitation enables attackers to execute arbitrary code within the context of the victim's browser session.\nPotential impacts include session hijacking, theft of sensitive authentication cookies, unauthorized actions performed on behalf of authenticated administrators, and redirection to malicious websites.\nBecause this vulnerability does not require authentication, it is highly accessible to attackers. It poses a significant risk to site integrity and visitor security, as the malicious content can be triggered merely by a user visiting the affected page.",
"technicalDetails": "The root cause of this vulnerability is improper neutralization of input during web page generation in the If-So Dynamic Content Personalization plugin (versions <= 1.10.1).\nThe plugin fails to adequately sanitize user-controllable input before echoing it back to the client-side environment. By injecting malicious payloads into specific parameters or inputs processed by the plugin, an attacker can manipulate the Document Object Model (DOM) of the rendered page.\nThis is classified as a Reflected XSS vulnerability, where the malicious script is embedded in a URL or a specific request parameter.\nThe attack flow begins when an unauthenticated attacker identifies an injection vector within the plugin that reflects input directly to the browser. The attacker crafts a payload—typically a <script> tag or an event handler such as 'onload' or 'onerror'—and embeds it into the vulnerable parameter.\nWhen a legitimate user, including administrative users, clicks a specially crafted link or visits a page triggering this input, the vulnerable plugin reflects the malicious script into the HTML source of the document. The user's browser, lacking context regarding the script's origin, executes the code with the permissions of the current session.\nBecause the payload executes within the context of the WordPress site's origin, it gains full access to cookies (if not protected by the HttpOnly flag), local storage, and session tokens. An attacker can leverage this to steal session cookies for account takeover, modify site content, or perform unauthorized administrative actions if the victim is a privileged user.\nThe vulnerability is reachable remotely over the network without requiring any prior authentication or privileges. The impact is essentially total compromise of the user's interaction with the affected page, as the script can perform any action available to the victim via the browser's JavaScript engine."
}