"value":"The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well."
"value":"Las versiones del complemento WP Statistics de WordPress anteriores a la 13.2.9 no escapan uno de los par\u00e1metros, lo que podr\u00eda permitir a usuarios autenticados realizar ataques de inyecci\u00f3n SQL. De forma predeterminada, la funci\u00f3n afectada est\u00e1 disponible para los usuarios con manage_options (admin+), sin embargo, el complemento tiene una configuraci\u00f3n para permitir que los usuarios con privilegios bajos tambi\u00e9n accedan a ella."