cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forif-so if-so

Direction: ascending
Jun 07, 2024

If-So Dynamic Content Personalization # CVE-2024-34820

CVE, Research URL

CVE-2024-34820

Date
Jun 11, 2024
Research Description
Missing Authorization vulnerability in If So Plugin If-So Dynamic Content Personalization.This issue affects If-So Dynamic Content Personalization: from n/a through 1.7.1.
Affected versions
max 1.7.1.1.
Status
vulnerable

If-So Dynamic Content Personalization # CVE-2023-51492

CVE, Research URL

CVE-2023-51492

Date
Feb 10, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If So Plugin If-So Dynamic Content Personalization allows Stored XSS.This issue affects If-So Dynamic Content Personalization: from n/a through 1.6.3.1.
Affected versions
max 1.7.
Status
vulnerable
Jul 14, 2024

If-So Dynamic Content Personalization # CVE-2024-5713

CVE, Research URL

CVE-2024-5713

Date
Jul 13, 2024
Research Description
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Affected versions
max 1.8.0.4.
Status
vulnerable

If-So Dynamic Content Personalization # CVE-2024-6070

CVE, Research URL

CVE-2024-6070

Date
Jul 13, 2024
Research Description
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
max 1.8.0.4.
Status
vulnerable
Nov 23, 2024

If-So Dynamic Content Personalization # CVE-2024-10796

CVE, Research URL

CVE-2024-10796

Date
Nov 21, 2024
Research Description
The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.2.1 via the 'ifso-show-post' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created via Elementor that they should not have access to.
Affected versions
max 1.9.2.2.
Status
vulnerable
May 19, 2025

If-So Dynamic Content Personalization # CVE-2024-5440

CVE, Research URL

CVE-2024-5440

Date
May 16, 2025
Research Description
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected versions
max 1.8.0.3.
Status
vulnerable
Sep 06, 2025

If-So Dynamic Content Personalization # CVE-2025-58602

CVE, Research URL

CVE-2025-58602

Date
Sep 03, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IfSo Dynamic Content If-So Dynamic Content Personalization allows Stored XSS. This issue affects If-So Dynamic Content Personalization: from n/a through 1.9.4.
Affected versions
max 1.9.4.1.
Status
vulnerable