OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-87971 (CVSS 7.1)

NVD · officialPublished Oct 7, 2026Risk 23/100

The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.

CVSS
7.1
AV:NetworkAC:LowPR:NoneUI:RequiredC:LowI:LowA:Low

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source