"value":"The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not validate and escape some settings, which could allow users with Admin privileges to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)"
"value":"El complemento de WordPress tagDiv Composer anterior a 4.2, utilizado como complemento de los temas Newspaper y Newsmag de tagDiv, no valida ni escapa a algunas configuraciones, lo que podr\u00eda permitir a los usuarios con privilegios de Administrador realizar ataques de Cross-Site Scripting almacenado incluso cuando la capacidad unfiltered_html est\u00e1 no permitida (por ejemplo, en configuraci\u00f3n multisitio)"