Multiple instances of user-controlled data were rendered in HTML output without proper sanitization or escaping, potentially allowing stored cross-site scripting (XSS) attacks. Additionally, certain administrative actions lacked adequate capability checks and nonce verification, which could expose the plugin to cross-site request forgery (CSRF) and unauthorized access. Output is now escaped using context-appropriate WordPress functions (esc_attr, esc_url, esc_html, wp_kses, wp_kses_post).

This vulnerability affects the following application versions:

  • Popup Builder by Forward Looking 4.1.15
  • Popup Builder by Forward Looking 4.2.0
  • Popup Builder by Forward Looking 4.2.2
  • Popup Builder by Forward Looking 4.2.3
  • Popup Builder by Forward Looking 4.2.4
  • Popup Builder by Forward Looking 4.2.5
  • Popup Builder by Forward Looking 4.2.6
  • Popup Builder by Forward Looking 4.2.7

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *