Cross-site Scripting Vulnerability in If-So Dynamic Content Personalization Plugin
CVE-2025-58602
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 September 2025
What is CVE-2025-58602?
The If-So Dynamic Content Personalization plugin is susceptible to Cross-site Scripting (XSS) due to improper handling of input during web page generation. An attacker can exploit this vulnerability to inject malicious scripts, which may be executed in the context of other users, potentially compromising sensitive information. All versions up to and including 1.9.4 are affected, making it crucial for users to apply the necessary updates to mitigate this security risk.
Affected Version(s)
If-So Dynamic Content Personalization <= 1.9.4