"value":"The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator"
},
{
"lang":"es",
"value":"El plugin Community Events de WordPress versiones anteriores a 1.4.8, no sanea, comprueba ni escapa de sus par\u00e1metros GET importrowscount y successimportcount antes de devolverlos a la p\u00e1gina de administraci\u00f3n, conllevando a un problema de tipo Cross-Site Scripting reflejado que ser\u00e1 ejecutado en el contexto de un administrador conectado"