"value":"The Product list Widget for Woocommerce WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high privilege one like admin)."
"value":"El complemento Product list Widget for Woocommerce de WordPress hasta la versi\u00f3n 1.0 no sanitiza ni escapa un par\u00e1metro antes de devolverlo a la p\u00e1gina, lo que genera un cross-site scripting reflejado que podr\u00eda usarse contra usuarios autenticados y no autenticados (como uno con privilegios altos como administraci\u00f3n)."