CVE-2026-87971

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-09: 110-09
Referenced assets1 URL
By indicator
Full discourse1 post
  • CERT-PY@CERTpy

    ⚠️ Vulnerabilidades en Plugins de WordPress ❗ CVE-2026-97188 ❗ CVE-2026-87971 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-plugins-de-wordpress-2/ https://t.co/AfhS08KAnY

    00000150
    6.7K followersView on X

Explore more