CVE Database /
CVE-2024-6070
CVE · Medium
CVE-2024-6070 — If-So Dynamic Content – Elementor & All Page Builders Personalization [if-so] < 1.8.0.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-6070
|
If-So Dynamic Content – Elementor & All Page Builders Personalization [if-so] < 1.8.0.4 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 1.8.0.4
|
1.8.0.4 |
2024-06-22 |
—
|
CVE-2024-6070
The If-So Dynamic Content Personalization plugin for WordPress contains a security flaw that allows authenticated attackers with administrator-level access to inject malicious scripts into pages. This vulnerability, present in versions up to 1.8.0.3, can be exploited through the "Geolocation License" field, which is not properly sanitized or escaped. As a result, when a user accesses the affected page, the injected script will execute, potentially leading to further attacks. This issue is specific to multi-site installations where unfiltered HTML has been disabled.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings