"value":"Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed."
},
{
"lang":"es",
"value":"Una entrada no comprobada y una falta de codificaci\u00f3n de salida en el plugin de WordPress Constant Contact Forms, versiones anteriores a 1.8.8, conllevan a m\u00faltiples vulnerabilidades de tipo Cross-Site Scripting Almacenado, que permit\u00edan a un usuario muy privilegiado (Editor+) inyectar c\u00f3digo JavaScript o HTML arbitrario en publicaciones donde la forma maliciosa est\u00e1 insertada"