"value":"The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the \"id\" parameter before submitting the query, leading to a SQLI exploitable by editors and above. Note: Due to the lack of CSRF check, the issue could also be exploited via a CSRF against a logged editor (or above)"
"value":"El complemento ArtPlacer Widget de WordPress anterior a 2.20.7 no sanitiza ni escapa del par\u00e1metro \"id\" antes de enviar la consulta, lo que genera un SQLI explotable por los editores y superiores. Nota: Debido a la falta de verificaci\u00f3n CSRF, el problema tambi\u00e9n podr\u00eda explotarse a trav\u00e9s de un CSRF contra un editor registrado (o superior)"