Eklenti güvenlik geçmişi
If-So Dynamic Content güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) If-So Dynamic Content – Elementor & All Page Builders Personalization eklentisi için 8 açık kaydı bulunuyor; en yenisi 7 Ekim 2026 tarihli. Bunların 3 tanesi kritik veya yüksek önemde, 4 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 1.10.2.
- Toplam kayıt
- 8
- Kritik veya yüksek
- 3
- Oturumsuz istismar
- 4
- Son kayıt
- 7 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.10.2 öncesi · Oturum açmadan istismar edilebilir
The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.
Türkçe kayıt ve ne yapmalısiteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.10.2 öncesi
The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.10.2 öncesi · Oturum açmadan istismar edilebilir
The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served as HTML, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who opens a crafted link.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.10.1 ve öncesi · Oturum açmadan istismar edilebilir
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Reflected XSS.This issue affects If-So Dynamic Content Personalization: from n/a through 1.10.1.
SQL enjeksiyonu
Etkilenen sürümler: 1.10 ve öncesi · Oturum açmadan istismar edilebilir
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.9.4 ve öncesi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Stored XSS.This issue affects If-So Dynamic Content Personalization: from n/a through <= 1.9.4.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.9.3.1 ve öncesi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Stored XSS.This issue affects If-So Dynamic Content Personalization: from n/a through <= 1.9.3.1.
hassas bilgi ifşası
Etkilenen sürümler: 1.9.2.1 ve öncesi
The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.2.1 via the 'ifso-show-post' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created via Elementor that they should not have access to.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.