WPHizmet

Eklenti güvenlik geçmişi

If-So Dynamic Content güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) If-So Dynamic Content – Elementor & All Page Builders Personalization eklentisi için 8 açık kaydı bulunuyor; en yenisi 7 Ekim 2026 tarihli. Bunların 3 tanesi kritik veya yüksek önemde, 4 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 1.10.2.

Toplam kayıt
8
Kritik veya yüksek
3
Oturumsuz istismar
4
Son kayıt
7 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-87971Yüksek · 7,17 Ekim 2026

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.10.2 öncesi · Oturum açmadan istismar edilebilir

    The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-87973Düşük · 3,11 Ekim 2026

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.10.2 öncesi

    The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page.

  • CVE-2026-87970Orta · 4,71 Ekim 2026

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.10.2 öncesi · Oturum açmadan istismar edilebilir

    The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served as HTML, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who opens a crafted link.

  • CVE-2026-100507Yüksek · 7,130 Eylül 2026

    yansıtılan siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.10.1 ve öncesi · Oturum açmadan istismar edilebilir

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Reflected XSS.This issue affects If-So Dynamic Content Personalization: from n/a through 1.10.1.

  • CVE-2026-66446Kritik · 9,313 Ağustos 2026

    SQL enjeksiyonu

    Etkilenen sürümler: 1.10 ve öncesi · Oturum açmadan istismar edilebilir

    Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.

  • CVE-2025-58602Orta · 6,53 Eylül 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.9.4 ve öncesi

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Stored XSS.This issue affects If-So Dynamic Content Personalization: from n/a through <= 1.9.4.

  • CVE-2025-49875Orta · 6,517 Haziran 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.9.3.1 ve öncesi

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Stored XSS.This issue affects If-So Dynamic Content Personalization: from n/a through <= 1.9.3.1.

  • CVE-2024-10796Orta · 4,321 Kasım 2024

    hassas bilgi ifşası

    Etkilenen sürümler: 1.9.2.1 ve öncesi

    The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.2.1 via the 'ifso-show-post' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created via Elementor that they should not have access to.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.