CVE · Medium

CVE-2024-6070 — If-So Dynamic Content – Elementor & All Page Builders Personalization [if-so] < 1.8.0.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6070 If-So Dynamic Content – Elementor & All Page Builders Personalization [if-so] < 1.8.0.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.8.0.4 1.8.0.4 2024-06-22

CVE-2024-6070

The If-So Dynamic Content Personalization plugin for WordPress contains a security flaw that allows authenticated attackers with administrator-level access to inject malicious scripts into pages. This vulnerability, present in versions up to 1.8.0.3, can be exploited through the "Geolocation License" field, which is not properly sanitized or escaped. As a result, when a user accesses the affected page, the injected script will execute, potentially leading to further attacks. This issue is specific to multi-site installations where unfiltered HTML has been disabled.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.