"value":"The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin."
"value":"El complemento Ditty WordPress anterior a la versi\u00f3n 3.1.25 no sanitiza ni escapa algunos par\u00e1metros y URL generadas antes de devolverlos en atributos, lo que genera un Cross-Site Scripting reflejado que podr\u00edan usarse contra usuarios con privilegios elevados, como el administrador."