"value":"The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin"
"value":"El complemento JSON Content Importer WordPress anterior a 1.5.4 no sanitiza ni escapa el par\u00e1metro de pesta\u00f1a antes de devolverlo a la p\u00e1gina, lo que genera Cross-Site Scripting Reflejado que podr\u00eda usarse contra usuarios con privilegios elevados, como el administrador."