Multiple instances of user-controlled data were rendered in HTML output without proper sanitization or escaping, potentially allowing stored cross-site scripting (XSS) attacks. Additionally, certain administrative actions lacked adequate capability checks and nonce verification, which could expose the plugin to cross-site request forgery (CSRF) and unauthorized access. Output is now escaped using context-appropriate WordPress functions (esc_attr, esc_url, esc_html, wp_kses, wp_kses_post).
This vulnerability affects the following application versions:
- Popup Builder by Forward Looking 4.1.15
- Popup Builder by Forward Looking 4.2.0
- Popup Builder by Forward Looking 4.2.2
- Popup Builder by Forward Looking 4.2.3
- Popup Builder by Forward Looking 4.2.4
- Popup Builder by Forward Looking 4.2.5
- Popup Builder by Forward Looking 4.2.6
- Popup Builder by Forward Looking 4.2.7