"value":"The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections."
},
{
"lang":"es",
"value":"El plugin 5 Stars Rating Funnel | RRatingg de WordPress versiones anteriores a 1.2.54, no sanea, comprueba y escapa de los identificadores de clientes potenciales antes de usarlos en una sentencia SQL por medio de la acci\u00f3n AJAX rrtngg_delete_leads, disponible para usuarios no autenticados, conllevando a un problema de inyecci\u00f3n SQL no autenticado. Se presenta un intento de sanear la entrada, usando la funci\u00f3n sanitize_text_field(), sin embargo dicha funci\u00f3n no est\u00e1 pensada para prevenir inyecciones SQL"