"value":"The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed."
},
{
"lang":"es",
"value":"El plugin Login with phone number de WordPress en versiones anteriores a la 1.3.8, no sanea y escapa de la configuraci\u00f3n del plugin, lo que podr\u00eda permitir a usuarios con altos privilegios llevar a cabo ataques de tipo Cross-Site Scripting incluso cuando la capacidad unfiltered_html est\u00e1 deshabilitado."