"value":"The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading to a stored cross-site scripting (XSS) vulnerability. Further it is also possible to inject PHP code, leading to a Remote Code execution (RCE) vulnerability, even if the DISALLOW_FILE_EDIT and DISALLOW_FILE_MOD constants are both set."
},
{
"lang":"es",
"value":"El plugin Ad Injection de WordPress versiones hasta 1.2.0.19, no sanea correctamente el cuerpo de los anuncios inyectados en las p\u00e1ginas, lo que permite a un usuario con altos privilegios (Admin+) inyectar HTML o javascript arbitrario incluso con unfiltered_html deshabilitado, conllevando a una vulnerabilidad de tipo Cross-Site Scripting (XSS) almacenada. Adem\u00e1s, tambi\u00e9n es posible inyectar c\u00f3digo PHP, conllevando a una vulnerabilidad de ejecuci\u00f3n de c\u00f3digo remota (RCE), incluso si las constantes DISALLOW_FILE_EDIT y DISALLOW_FILE_MOD est\u00e1n establecidas"