What the vulnerability does
01Description
Missing Authorization vulnerability in If So Plugin If-So Dynamic Content Personalization.This issue affects If-So Dynamic Content Personalization: from n/a through 1.7.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in If So Plugin If-So Dynamic Content Personalization.This issue affects If-So Dynamic Content Personalization: from n/a through 1.7.1.
Explanation of Vulnerability in Simple Terms
The If-So Dynamic Content Personalization plugin for WordPress contains an authorization bypass that allows unauthenticated attackers to modify site content and availability settings. An attacker can send network requests without authentication to alter integrity and availability of the site. This affects versions up to 1.7.1. Update to a version newer than 1.7.1 to resolve the issue.
What an attacker can do
Modify site content and disable features without logging in.
Potential impact on your site
Attackers can alter your site's published content and disable functionality without your knowledge or permission.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities