Sceawere

Vulnerability Detail

CVE-2026-100507UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in If-So

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
If-So Dynamic Content
Product
If-So Dynamic Content Personalization
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:14.577Z",
  "pubdate": "2026-09-30T13:17:14.577Z",
  "executiveSummary": "The If-So Dynamic Content Personalization plugin for WordPress, in versions 1.10.1 and below, contains a critical security vulnerability involving unauthenticated Cross-Site Scripting (XSS).\nThis vulnerability allows remote, unauthenticated attackers to inject malicious JavaScript into the rendered web pages of a target site.\nThe flaw stems from insufficient input sanitization of user-supplied data, which is subsequently reflected back to users without proper encoding.\nSuccessful exploitation enables attackers to execute arbitrary code within the context of the victim's browser session.\nPotential impacts include session hijacking, theft of sensitive authentication cookies, unauthorized actions performed on behalf of authenticated administrators, and redirection to malicious websites.\nBecause this vulnerability does not require authentication, it is highly accessible to attackers. It poses a significant risk to site integrity and visitor security, as the malicious content can be triggered merely by a user visiting the affected page.",
  "technicalDetails": "The root cause of this vulnerability is improper neutralization of input during web page generation in the If-So Dynamic Content Personalization plugin (versions <= 1.10.1).\nThe plugin fails to adequately sanitize user-controllable input before echoing it back to the client-side environment. By injecting malicious payloads into specific parameters or inputs processed by the plugin, an attacker can manipulate the Document Object Model (DOM) of the rendered page.\nThis is classified as a Reflected XSS vulnerability, where the malicious script is embedded in a URL or a specific request parameter.\nThe attack flow begins when an unauthenticated attacker identifies an injection vector within the plugin that reflects input directly to the browser. The attacker crafts a payload—typically a <script> tag or an event handler such as 'onload' or 'onerror'—and embeds it into the vulnerable parameter.\nWhen a legitimate user, including administrative users, clicks a specially crafted link or visits a page triggering this input, the vulnerable plugin reflects the malicious script into the HTML source of the document. The user's browser, lacking context regarding the script's origin, executes the code with the permissions of the current session.\nBecause the payload executes within the context of the WordPress site's origin, it gains full access to cookies (if not protected by the HttpOnly flag), local storage, and session tokens. An attacker can leverage this to steal session cookies for account takeover, modify site content, or perform unauthorized administrative actions if the victim is a privileged user.\nThe vulnerability is reachable remotely over the network without requiring any prior authentication or privileges. The impact is essentially total compromise of the user's interaction with the affected page, as the script can perform any action available to the victim via the browser's JavaScript engine."
}
CVE-2026-100507: Unauthenticated XSS in If-So (HIGH Severity, CVSS: 7.1) | Sceawere