"value":"The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed"
},
{
"lang":"es",
"value":"El plugin VikBooking Hotel Booking Engine & PMS de WordPress versiones anteriores a 1.5.8, no escapa a varias configuraciones antes de mostrarlas en atributos, lo que podr\u00eda permitir a usuarios con altos privilegios, como los administradores, llevar a cabo ataques de tipo Cross-Site Scripting incluso cuando unfiltered_html est\u00e1 deshabilitado"