"value":"The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin"
"value":"El complemento de WordPress Estatik Real Estate Plugin anterior a 4.1.1 no sanitiza ni escapa varios par\u00e1metros y URL generadas antes de devolverlos en atributos, lo que genera cross site scripting reflejado que podr\u00eda usarse contra usuarios con privilegios elevados, como administradores."