The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[message]` parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This is due to the `arv_lb_options_val()` sanitize callback returning user input without any sanitization, and the stored `message` value being output in the `genLB()` function without escaping. This makes it possible for authenticated attackers, with Administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses a page or post with the lightbox enabled.
The Multi Functional Flexi Lightbox WordPress plugin versions up to 1.2 contains a Stored XSS vulnerability in the arv_lb[message] parameter due to insufficient input sanitization and output escaping. Authenticated administrators can inject malicious scripts that execute for all users viewing pages with the lightbox enabled.
تحتوي إضافة Multi Functional Flexi Lightbox لـ WordPress على ثغرة Stored XSS في معامل arv_lb[message] حيث تفشل دالة arv_lb_options_val() في تنظيف المدخلات بشكل صحيح. يمكن للمسؤولين المصرح لهم حقن نصوص برمجية ضارة تُنفذ عند وصول أي مستخدم إلى صفحة تحتوي على Lightbox مفعل.
The Multi Functional Flexi Lightbox WordPress plugin versions up to 1.2 contains a Stored XSS vulnerability in the arv_lb[message] parameter due to insufficient input sanitization and output escaping. Authenticated administrators can inject malicious scripts that execute for all users viewing pages with the lightbox enabled.
Update the Multi Functional Flexi Lightbox plugin to version 1.3 or later immediately. Implement strict input validation and output escaping for the arv_lb[message] parameter. Restrict administrator access to trusted users only and audit existing lightbox configurations for malicious content.
قم بتحديث إضافة Multi Functional Flexi Lightbox إلى الإصدار 1.3 أو أحدث فوراً. طبق التحقق الصارم من المدخلات والترميز الآمن لمعامل arv_lb[message]. قيد الوصول الإداري للمستخدمين الموثوقين فقط وتدقيق إعدادات Lightbox الموجودة للتحقق من المحتوى الضار.